@lingo.dev/compiler is vulnerable to Information Disclosure
15
Low Risk
Affected versions of this package transmitted raw user email addresses to PostHog as the distinct_id, exposing personally identifiable information (PII) through analytics telemetry. An attacker with access to analytics dashboards, logs, or compromised telemetry pipelines could collect and correlate these email addresses to identify users across sessions and environments. This leakage could facilitate user profiling, targeted phishing, or correlation with other breached datasets. The fix hashes emails using SHA-256 before transmission, preserving analytics correlation while preventing exposure of raw PII.
You are affected if you are using a version that falls within the vulnerable range.
@lingo.dev/compiler is vulnerable to Information Disclosure in versions 0.0.1 - 0.3.9.
Upgrade the @lingo.dev/compiler library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant