Intel

AIKIDO-2026-253906

@vendure/core is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

Exposure of Sensitive Information to an Unauthorized ActorGHSA-32jm-mf7r-7qw5 Published Today

65

Medium Risk

This Affects:

JS@vendure/core
1.4.0 - 3.7.2
Fixed in 3.7.3
Are you affected? Scan for Free

TL;DR

RequestContext serialization writes the whole context, including the session object with its bearer token and a shallow clone of the Express request with its HTTP headers, into persisted job-queue data. Administrators holding ReadSettings or ReadSystem permission can read that job data through the Admin API and recover session tokens and request headers. The fix stops the Admin API from returning session tokens in job-data fields.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and administrators with ReadSettings or ReadSystem permission can read job-queue data.

Background info

@vendure/core is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 1.4.0 - 3.7.2.

How to fix this

Upgrade the @vendure/core library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform