Intel

AIKIDO-2025-10553

github.com/ans-group/sdk-go is vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere

Exposure of Sensitive System Information to an Unauthorized Control Sphere Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Aug 18, 2025

10

Low Risk

This Affects:

gogithub.com/ans-group/sdk-go
1.22.2 - 1.25.0
Fixed in 1.25.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package contain an information exposure vulnerability where the InvokeRequest method logs all HTTP request headers when handling arbitrary headers without redaction. An attacker could exploit this vulnerability by accessing these logs to harvest credentials; captured tokens would then enable unauthorized API access, privilege escalation, or session hijacking under the victim's identity.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/ans-group/sdk-go is vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere in versions 1.22.2 - 1.25.0.

How to fix this

Upgrade the github.com/ans-group/sdk-go library to the patch version.