Intel

AIKIDO-2026-371568

openai is vulnerable to Information Disclosure

Information Disclosure Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Yesterday

59

Medium Risk

This Affects:

JSopenai
4.41.0 - 7.4.0
Fixed in 7.5.0
Are you affected? Scan for Free

TL;DR

The AzureOpenAI client attaches a static API key in the api-key header and follows HTTP redirects by default. When the configured endpoint returns a redirect to a different host, the redirected request still includes api-key, which discloses the API key to the redirect target. Custom base URLs, self hosted proxies, and compromised endpoints can produce that redirect. The fix sets redirect to manual for requests that include api-key, so the client stops at the redirect and does not send the key to the next host.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your AzureOpenAI client sends a static api-key to an endpoint that can redirect to another host.

Background info

openai is vulnerable to Information Disclosure in versions 4.41.0 - 7.4.0.

How to fix this

Upgrade the openai library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform