headroom-ai is vulnerable to Information Disclosure
64
Medium Risk
The proxy keeps a single in-process CCR context tracker that is shared across every session, project, and client. Because tracked compressions carry no workspace identity, proactive context expansion matches and injects one project's compressed content into an unrelated project's request based only on lexical keyword overlap. This exposes source and context from one workspace inside another workspace's model session. The fix adds a required per-workspace key to every tracked entry and fails closed when the workspace cannot be resolved so expansion never crosses project boundaries.
You are affected if you are using a version that falls within the vulnerable range and you run the proxy with CCR proactive context expansion enabled in default non-cache mode.
headroom-ai is vulnerable to Information Disclosure in versions 0.2.2 - 0.22.4.
Upgrade the headroom-ai library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant