statsig-node is vulnerable to Insertion of Sensitive Information into Log File
20
Low Risk
Affected versions of this package are vulnerable to sensitive key exposure via error logging, where the StatsigInitializeFromNetworkError method inadvertently writes secret keys to log files. An attacker could exploit this by gaining read access to log storage (via compromised systems, misconfigured cloud permissions, or directory traversal flaws), harvesting exposed keys to impersonate legitimate services, hijacking user sessions, escalating privileges, or compromising dependent systems by reusing stolen credentials.
You are affected if you are using a version that falls within the vulnerable range.
statsig-node is vulnerable to Insertion of Sensitive Information into Log File in versions 5.11.0 - 6.4.4.
Upgrade the statsig-node library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant