Intel

AIKIDO-2025-10450

@cubejs-backend/cubesql is vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere

Exposure of Sensitive System Information to an Unauthorized Control Sphere Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jul 10, 2025

30

Low Risk

This Affects:

JS@cubejs-backend/cubesql
0.34.11 - 1.3.34
Fixed in 1.3.35
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Sensitive Information Exposure in Application Logs due to improper handling of security context during error logging. When role-switching operations fail, the system erroneously writes full HTTP authentication context details, including access tokens and base paths, into log files in plain text. Attackers with access to these logs can harvest information to impersonate legitimate users, escalate privileges, bypass authentication controls, or directly access protected resources without authorization.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@cubejs-backend/cubesql is vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere in versions 0.34.11 - 1.3.34.

How to fix this

Upgrade the @cubejs-backend/cubesql library to the patch version.