Intel

AIKIDO-2025-10274

@hono/arktype-validator is vulnerable to Generation of Error Message Containing Sensitive Information

Generation of Error Message Containing Sensitive Information Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

15

Low Risk

This Affects:

JS@hono/arktype-validator
1.0.0 - 2.0.0
Fixed in 2.0.1

TL;DR

Affected versions of this package may unintentionally leak restricted or sensitive data fields in error responses. When an operation fails, instead of properly sanitizing or omitting protected fields, the application includes them in the returned error message. An attacker could exploit this behavior to gain access to confidential information.

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges.

Background info

@hono/arktype-validator is vulnerable to Generation of Error Message Containing Sensitive Information in versions 1.0.0 - 2.0.0.

How to fix this

Upgrade the @hono/arktype-validator library to the patch version.