Intel

AIKIDO-2025-10479

@1password/connect is vulnerable to Insertion of Sensitive Information into Log File

Insertion of Sensitive Information into Log File Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jul 21, 2025

20

Low Risk

This Affects:

JS@1password/connect
1.0.1 - 1.4.1
Fixed in 1.4.2
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to sensitive information exposure in error logs due to improper exception handling. When the SDK encounters an error communicating with the 1Password Connect server, it throws an Exception containing the full HTTP request details, including the Authorization header bearing the sensitive Connect access token. An attacker with access to these log files can easily extract the exposed access token and use it to gain unauthorized access to the 1Password Connect API, potentially compromising secrets managed by 1Password.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@1password/connect is vulnerable to Insertion of Sensitive Information into Log File in versions 1.0.1 - 1.4.1.

How to fix this

Upgrade the @1password/connect library to the patch version.