Intel

AIKIDO-2025-10371

box-sdk-gen is vulnerable to Observable Timing Discrepancy

Observable Timing Discrepancy Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 13, 2025

30

Low Risk

This Affects:

Pythonbox-sdk-gen
0.1.0 - 1.14.0
Fixed in 1.15.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package use a non-constant-time string comparison to verify HMAC signatures, allowing attackers to exploit timing differences—by measuring response times—to gradually guess the correct signature byte-by-byte, potentially forging valid requests.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

box-sdk-gen is vulnerable to Observable Timing Discrepancy in versions 0.1.0 - 1.14.0.

How to fix this

Upgrade the box-sdk-gen library to the patch version.