Intel

AIKIDO-2025-10370

box-typescript-sdk-gen is vulnerable to Observable Timing Discrepancy

Observable Timing Discrepancy Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 13, 2025

30

Low Risk

This Affects:

JSbox-typescript-sdk-gen
0.1.0 - 1.15.1
Fixed in 1.16.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package use a non-constant-time string comparison to verify HMAC signatures, allowing attackers to exploit timing differences—by measuring response times—to gradually guess the correct signature byte-by-byte, potentially forging valid requests.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

box-typescript-sdk-gen is vulnerable to Observable Timing Discrepancy in versions 0.1.0 - 1.15.1.

How to fix this

Upgrade the box-typescript-sdk-gen library to the patch version.