Intel

AIKIDO-2025-10613

botbuilder is vulnerable to Generation of Error Message Containing Sensitive Information

Generation of Error Message Containing Sensitive Information Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Sep 9, 2025

25

Low Risk

This Affects:

JSbotbuilder
4.7.0 - 4.23.2
Fixed in 4.23.3
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Information Disclosure via Error Message due to improper error handling in the handleError function of channelServiceRoutes, which directly sends sensitive error traces (including stack details) in HTTP responses. This allows attackers to deliberately trigger errors and extract internal application logic, file paths, or system details by analyzing the verbose error messages, facilitating further exploits like targeted attacks or reconnaissance.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

botbuilder is vulnerable to Generation of Error Message Containing Sensitive Information in versions 4.7.0 - 4.23.2.

How to fix this

Upgrade the botbuilder library to the patch version.