Intel

AIKIDO-2025-10849

clevertap-web-sdk is vulnerable to Improper Input Validation

Improper Input Validation Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Nov 27, 2025

55

Medium Risk

This Affects:

JSclevertap-web-sdk
1.0.0 - 2.3.1
Fixed in 2.3.2
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable due to insufficient input validation in multiple parts of the codebase, particularly when parsing JSON data for cookies or localStorage entries such as GUID, session, backups, or inbox. Because these values are processed without proper validation or sanitization, an attacker can supply malformed or malicious JSON that triggers unexpected behavior, potentially leading to data corruption, application errors, or further exploitation depending on how the parsed data is used.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

clevertap-web-sdk is vulnerable to Improper Input Validation in versions 1.0.0 - 2.3.1.

How to fix this

Upgrade the clevertap-web-sdk library to the patch version.