Intel

AIKIDO-2025-10573

Bybit.Net is vulnerable to Generation of Error Message Containing Sensitive Information

Generation of Error Message Containing Sensitive Information Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Aug 25, 2025

20

Low Risk

This Affects:

dotnetBybit.Net
3.8.1 - 5.6.0
Fixed in 5.6.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Information Disclosure via Detailed Error Messages due to improperly returning a generic ServerError containing the full exception object even for HTTP 401 Unauthorized responses. An attacker can exploit this vulnerability by systematically probing endpoints with invalid credentials, causing the application to leak sensitive internal information, framework details, or database queries within the exception message of the 401 response, which significantly aids in crafting more sophisticated attacks.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

Bybit.Net is vulnerable to Generation of Error Message Containing Sensitive Information in versions 3.8.1 - 5.6.0.

How to fix this

Upgrade the Bybit.Net library to the patch version.