repomix is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
25
Low Risk
Affected versions of this package are vulnerable to sensitive data leakage where secretlint logs could expose private keys and other confidential information during repomix execution, particularly when coding agents transmit terminal output to LLM providers. An attacker could exploit this by intercepting or accessing the logged output to harvest exposed secrets, potentially compromising systems or accounts tied to the leaked credentials.
You are affected if you are using a version that falls within the vulnerable range.
repomix is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.1.32 - 0.3.9.
Upgrade the repomix library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant