livekit-agents is vulnerable to Insertion of Sensitive Information into Log File
40
Medium Risk
The agent framework writes plugin credentials into worker logs and error output when a plugin's WebSocket handshake fails. Authentication headers and credential-bearing URLs are included in propagated exceptions, and the connection-pool prewarm path logs the exception details. As a result configured API keys can appear in plaintext in agent logs and be captured by log aggregation systems. The fix redacts API keys from handshake errors, suppresses exception chaining, and limits logging to exception types.
You are affected if you are using a version that falls within the vulnerable range and a plugin whose API credentials are sent in a WebSocket handshake experiences a handshake failure that is logged.
livekit-agents is vulnerable to Insertion of Sensitive Information into Log File in versions 0.0.1 - 1.6.9.
Upgrade the livekit-agents library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant