Intel

AIKIDO-2025-11004

better-ccflare is vulnerable to Exposure of Sensitive Information

Exposure of Sensitive Information Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Dec 30, 2025

55

Medium Risk

This Affects:

JSbetter-ccflare
3.0.0 - 3.0.3
Fixed in 3.0.4
Are you affected? Scan for Free

TL;DR

Affected versions of this package may expose sensitive information by unintentionally forwarding the client API key to OAuth providers. When both Authorization and x-api-key headers are present, only the Authorization header is removed, allowing the API key to be leaked to upstream services. This change ensures both headers are stripped before provider-specific credentials are applied, preventing unintended disclosure of authentication data.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

better-ccflare is vulnerable to Exposure of Sensitive Information in versions 3.0.0 - 3.0.3.

How to fix this

Upgrade the better-ccflare library to the patch version.