Intel

AIKIDO-2026-108451

@ai-sdk/harness-acp is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

Exposure of Sensitive Information to an Unauthorized ActorGHSA-4mqq-99j3-3hmv Published 2 days ago

75

High Risk

This Affects:

JS@ai-sdk/harness-acp
0.0.1 - 1.0.70
Fixed in 1.0.71
Are you affected? Scan for Free

TL;DR

The @ai-sdk/harness-acp adapter resumes a saved agent session by reusing the credential placeholder map stored with that session's prior lifecycle state. When the resumed session introduces a credential environment variable absent from that saved map, the adapter forwards the real credential value into the sandbox instead of substituting a placeholder. Code or agent activity running inside the resumed sandbox can then read and exfiltrate the exposed credential, such as a model provider API key or source control token. The fix refreshes the placeholder map against the current authentication environment before resuming the session.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you resume a saved agent session after the authentication environment introduces a credential variable absent from the session's placeholder map.

Background info

@ai-sdk/harness-acp is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.1 - 1.0.70.

How to fix this

Upgrade the @ai-sdk/harness-acp and/or the @ai-sdk/harness-opencode library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform