Intel

AIKIDO-2025-10424

repomix is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

Exposure of Sensitive Information to an Unauthorized Actor Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 30, 2025

25

Low Risk

This Affects:

JSrepomix
0.1.32 - 0.3.9
Fixed in 1.0.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to sensitive data leakage where secretlint logs could expose private keys and other confidential information during repomix execution, particularly when coding agents transmit terminal output to LLM providers. An attacker could exploit this by intercepting or accessing the logged output to harvest exposed secrets, potentially compromising systems or accounts tied to the leaked credentials.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

repomix is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.1.32 - 0.3.9.

How to fix this

Upgrade the repomix library to the patch version.