Intel

AIKIDO-2026-567630

slack-morphism is vulnerable to Information Disclosure

Information DisclosureGHSA-26w4-8w32-4x3v Published 5 days ago

53

Medium Risk

This Affects:

RUSTslack-morphism
1.0.0 - 2.27.0
Fixed in 2.28.0
Are you affected? Scan for Free

TL;DR

Slack Morphism's signature verifier stores the correct HMAC for an invalid request in SlackEventWrongSignatureError.generated_hash, and both Debug and Display print that value, so a default listener error handler logs the correct signature when verification fails. A request with a chosen timestamp and body and an invalid signature makes the verifier compute and leak that request's correct signature into the logs, so the same request can be resent within the five minute freshness window and pass verification without the signing secret. The fix drops the expected signature from the error entirely and truncates the received signature to a short prefix before formatting.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and someone outside your trust boundary can both reach your Slack event endpoint and read the resulting signature verification error logs.

Background info

slack-morphism is vulnerable to Information Disclosure in versions 1.0.0 - 2.27.0.

How to fix this

Upgrade the slack-morphism library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform