Intel

AIKIDO-2025-10634

zapier-platform-core is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

Exposure of Sensitive Information to an Unauthorized Actor Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Sep 11, 2025

25

Low Risk

This Affects:

JSzapier-platform-core
0.0.1 - 17.7.0
Fixed in 17.7.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package may inadvertently expose sensitive information, as the access_token value can be included in error responses. This disclosure could allow attackers to obtain authentication credentials and gain unauthorized access.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

zapier-platform-core is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.1 - 17.7.0.

How to fix this

Upgrade the zapier-platform-core library to the patch version.