Intel

AIKIDO-2026-10235

r2luna/brain is vulnerable to Information Disclosure

Information Disclosure Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Feb 25, 2026

20

Low Risk

This Affects:

PHPr2luna/brain
1.0.0 - 2.1.0
Fixed in 2.2.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package do not properly support the #[Sensitive] attribute to mark and redact confidential payload properties, causing sensitive values (e.g., keys, tokens, or secrets) to be exposed in logs, JSON serialization, debug output, and event payloads; an attacker with access to application logs, monitoring systems, or serialized task data could exploit this by harvesting leaked secrets to gain unauthorized access, escalate privileges, or perform lateral movement within the environment.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

r2luna/brain is vulnerable to Information Disclosure in versions 1.0.0 - 2.1.0.

How to fix this

Upgrade the r2luna/brain library to the patch version.