Intel

AIKIDO-2026-479300

@evershop/evershop is vulnerable to Exposure of Sensitive Information

Exposure of Sensitive InformationCVE-2026-28213 Published 3 days ago

98

Critical Risk

This Affects:

JS@evershop/evershop
0.0.1 - 2.1.0
Fixed in 2.1.1
Are you affected? Scan for Free

TL;DR

The customer forgot-password API returns the generated password reset token directly in its HTTP response when a target email address is supplied. Because the token is disclosed to the requester, a request can be made for another customer's email, the token read from the response, and a new password set for that account. The fix stops returning the reset token in the API response.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@evershop/evershop is vulnerable to Exposure of Sensitive Information in versions 0.0.1 - 2.1.0.

How to fix this

Upgrade the @evershop/evershop library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform