Intel

AIKIDO-2026-10740

sentry is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

Exposure of Sensitive Information to an Unauthorized Actor Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published May 6, 2026

64

Medium Risk

This Affects:

JSsentry
0.2.0 - 0.29.1
Fixed in 0.30.0
Are you affected? Scan for Free

TL;DR

In vulnerable versions, credentials—including tokens, environment/rc-provided hosts, and custom headers—could be sent to untrusted or attacker-controlled destinations, exposing them to credential exfiltration or phishing attacks. The vulnerability was due to missing checks that allowed Sentry tokens and custom headers to be included with requests to arbitrary URLs, rather than ensuring they were only sent to trusted Sentry hosts.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

sentry is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.2.0 - 0.29.1.

How to fix this

Upgrade the sentry library to the patch version.