Intel

AIKIDO-2025-10366

github.com/livekit/protocol is vulnerable to Exposure of Sensitive Information

Exposure of Sensitive Information Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 11, 2025

25

Low Risk

This Affects:

GOgithub.com/livekit/protocol
0.1.0 - 1.39.0
Fixed in 1.39.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package may expose sensitive information. In the patched version, the CheckCredentials function validates whether the room configuration contains sensitive credentials and blocks the response if so, effectively preventing credential leakage to the client.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/livekit/protocol is vulnerable to Exposure of Sensitive Information in versions 0.1.0 - 1.39.0.

How to fix this

Upgrade the github.com/livekit/protocol library to the patch version.