Intel

AIKIDO-2025-10803

error_tracker is vulnerable to Generation of Error Message Containing Sensitive Information

Generation of Error Message Containing Sensitive Information Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Nov 12, 2025

20

Low Risk

This Affects:

ELIXIRerror_tracker
0.0.1 - 0.6.0
Fixed in 0.7.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to exposure of Authorization and Cookie headers via error logging: under certain failure paths the application logs request headers without redaction, causing sensitive credentials (e.g., bearer tokens and session cookies) to be written in plain text to logs. An attacker or any party with access to those logs could use the leaked values to impersonate users or escalate privileges.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

error_tracker is vulnerable to Generation of Error Message Containing Sensitive Information in versions 0.0.1 - 0.6.0.

How to fix this

Upgrade the error_tracker library to the patch version.