Intel

AIKIDO-2026-511457

@composio/openai is vulnerable to Insertion of Sensitive Information into Log File

Insertion of Sensitive Information into Log File Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Today

30

Low Risk

This Affects:

JS@composio/openai
0.1.36 - 0.12.1
Fixed in 0.12.2
Are you affected? Scan for Free

TL;DR

The OpenAI Responses provider logs the full MCP server response to standard output with console.log inside wrapMcpServerResponse. That response contains each MCP server URL, and those URLs can embed authentication tokens or other secrets in their path. Applications that connect MCP servers through this provider leak the credential bearing URLs into stdout and any captured log output.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you connect MCP servers whose URLs contain authentication tokens or other secrets.

Background info

@composio/openai is vulnerable to Insertion of Sensitive Information into Log File in versions 0.1.36 - 0.12.1.

How to fix this

Upgrade the @composio/openai library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform