Intel

AIKIDO-2025-10855

better-ccflare is vulnerable to Insertion of Sensitive Information Into Sent Data

Insertion of Sensitive Information Into Sent Data Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

45

Medium Risk

This Affects:

JSbetter-ccflare
1.2.28 - 3.0.0
Fixed in 3.0.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Authorization Header Credential Leakage due to insufficient sanitization of client Authorization headers, which could allow attackers to intercept leaked credentials from upstream providers. This security flaw involves improper management of authentication headers across all provider types, including OAuth, API key, Anthropic-compatible, and OpenAI-compatible providers. An attacker exploiting this vulnerability could gain unauthorized access to client credentials by monitoring or manipulating requests to upstream providers, potentially leading to account takeover or further malicious activities.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

better-ccflare is vulnerable to Insertion of Sensitive Information Into Sent Data in versions 1.2.28 - 3.0.0.

How to fix this

Upgrade the better-ccflare library to the patch version.