Intel

AIKIDO-2025-10175

github.com/buildkite/agent/v3 is vulnerable to Exposure of Sensitive Information

Exposure of Sensitive Information Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Mar 25, 2025

24

Low Risk

This Affects:

GOgithub.com/buildkite/agent/v3
3.0.0 - 3.95.0
Fixed in 3.95.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package may expose sensitive information, as secrets accessible to the agent through environment variables are not properly redacted from annotations, metadata values, and step updates. To align with the redaction applied to job logs, secrets are now automatically masked in these areas. If necessary, this behavior can be disabled by passing the --redacted-vars='' flag to the annotate, meta-data set, or step update command.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/buildkite/agent/v3 is vulnerable to Exposure of Sensitive Information in versions 3.0.0 - 3.95.0.

How to fix this

Upgrade the github.com/buildkite/agent/v3 library to the patch version.