Intel

AIKIDO-2026-10326

@lingo.dev/compiler is vulnerable to Information Disclosure

Information Disclosure Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Mar 10, 2026

15

Low Risk

This Affects:

JS@lingo.dev/compiler
0.0.1 - 0.3.9
Fixed in 0.3.10
Are you affected? Scan for Free

TL;DR

Affected versions of this package transmitted raw user email addresses to PostHog as the distinct_id, exposing personally identifiable information (PII) through analytics telemetry. An attacker with access to analytics dashboards, logs, or compromised telemetry pipelines could collect and correlate these email addresses to identify users across sessions and environments. This leakage could facilitate user profiling, targeted phishing, or correlation with other breached datasets. The fix hashes emails using SHA-256 before transmission, preserving analytics correlation while preventing exposure of raw PII.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@lingo.dev/compiler is vulnerable to Information Disclosure in versions 0.0.1 - 0.3.9.

How to fix this

Upgrade the @lingo.dev/compiler library to the patch version.