Intel

AIKIDO-2026-10332

github.com/goreleaser/goreleaser/v2 is vulnerable to Insertion of Sensitive Information into Log File

Insertion of Sensitive Information into Log File Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Mar 10, 2026

18

Low Risk

This Affects:

GOgithub.com/goreleaser/goreleaser/v2
2.0.0 - 2.13.3
Fixed in 2.14.0
Are you affected? Scan for Free

TL;DR

Affected versions of goreleaser are vulnerable to insertion of sensitive information into log files due to insufficient sanitization of values written to logs. Under certain conditions, authentication tokens or other sensitive configuration values may be included in log output, potentially exposing secrets to users who have access to build or CI logs. An attacker with access to these logs could retrieve the exposed credentials and use them to access external services or repositories.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/goreleaser/goreleaser/v2 is vulnerable to Insertion of Sensitive Information into Log File in versions 2.0.0 - 2.13.3.

How to fix this

Upgrade the github.com/goreleaser/goreleaser/v2 library to the patch version.