Intel

AIKIDO-2025-10821

github.com/buildkite/agent/v3 is vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere

Exposure of Sensitive System Information to an Unauthorized Control Sphere Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Nov 19, 2025

20

Low Risk

This Affects:

GOgithub.com/buildkite/agent/v3
3.0.0 - 3.112.0
Fixed in 3.113.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Information Disclosure, where a refactor introduced an unhandled error in the secrets rejection function, allowing pipelines with cleartext secrets, such as passwords or API keys, to be uploaded even when the --reject-secrets flag was enabled. An attacker could exploit this vulnerability by deliberately submitting malicious pipeline configurations that contain exposed secrets, thereby bypassing intended safeguards and potentially leading to unauthorized access or data exposure.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/buildkite/agent/v3 is vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere in versions 3.0.0 - 3.112.0.

How to fix this

Upgrade the github.com/buildkite/agent/v3 library to the patch version.