Intel

AIKIDO-2025-10374

unleash-server is vulnerable to Use of Weak Hash

Use of Weak Hash Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 16, 2025

20

Low Risk

This Affects:

JSunleash-server
6.5.0 - 7.0.0
Fixed in 7.0.1
Are you affected? Scan for Free

TL;DR

Affected versions of the package use an algorithm that produces a digest (output value) not meeting security expectations for a hash function, allowing an adversary to reasonably determine the original input. In the patched version, MD5 is replaced with SHA-256 when hashing email addresses.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

unleash-server is vulnerable to Use of Weak Hash in versions 6.5.0 - 7.0.0.

How to fix this

Upgrade the unleash-server library to the patch version.