Intel

AIKIDO-2025-10864

rollbar/rollbar is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

Exposure of Sensitive Information to an Unauthorized Actor Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

25

Low Risk

This Affects:

PHProllbar/rollbar
0.0.1 - 4.1.4
Fixed in 4.2.0

TL;DR

Affected versions of this package may expose sensitive data because of a failure in the scrubbing functionality, potentially leaking confidential information such as passwords, tokens, or personally identifiable data.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

rollbar/rollbar is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.1 - 4.1.4.

How to fix this

Upgrade the rollbar/rollbar library to the patch version.