Intel

AIKIDO-2025-10530

statsig-node is vulnerable to Insertion of Sensitive Information into Log File

Insertion of Sensitive Information into Log File Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Aug 5, 2025

20

Low Risk

This Affects:

JSstatsig-node
5.11.0 - 6.4.4
Fixed in 6.4.5
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to sensitive key exposure via error logging, where the StatsigInitializeFromNetworkError method inadvertently writes secret keys to log files. An attacker could exploit this by gaining read access to log storage (via compromised systems, misconfigured cloud permissions, or directory traversal flaws), harvesting exposed keys to impersonate legitimate services, hijacking user sessions, escalating privileges, or compromising dependent systems by reusing stolen credentials.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

statsig-node is vulnerable to Insertion of Sensitive Information into Log File in versions 5.11.0 - 6.4.4.

How to fix this

Upgrade the statsig-node library to the patch version.