Intel

AIKIDO-2026-10109

pulpcore is vulnerable to Generation of Error Message Containing Sensitive Information

Generation of Error Message Containing Sensitive Information Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

20

Low Risk

This Affects:

PYTHONpulpcore
3.0.0 - 3.101.0
Fixed in 3.102.0

TL;DR

Affected versions of this package are vulnerable to information disclosure via exception tracebacks from failed tasks, where tracebacks expose sensitive data such as internal system paths or configuration details through the API. An attacker could exploit this by repeatedly triggering task failures or querying the API to access these tracebacks, thereby extracting confidential information.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

pulpcore is vulnerable to Generation of Error Message Containing Sensitive Information in versions 3.0.0 - 3.101.0.

How to fix this

Upgrade the pulpcore library to the patch version.

Background Info