openai is vulnerable to Exposure of Sensitive Information
59
Medium Risk
The openai client supports X.509 workload-identity authentication over mutual TLS, where the application supplies an Undici dispatcher and the SDK forwards the client certificate and request without independently verifying the transport. The approved-origin check does not reject credential-bearing query parameters and screens only a fixed set of sensitive headers, and target and CONNECT-proxy trust are not isolated, so the workload certificate and other authentication credentials can leave the strictly verified mTLS origin. This can expose the client certificate, private key, or exchanged access token to a proxy or an unverified endpoint. The fix adds an SDK-owned credential that enforces verified TLS, isolates proxy trust, restricts requests to the approved origin, and rejects conflicting header and query credentials.
You are affected if you are using a version that falls within the vulnerable range and you use X.509 workload-identity authentication with a caller-supplied dispatcher or CONNECT proxy.
openai is vulnerable to Exposure of Sensitive Information in versions 7.6.0 - 7.7.0.
Upgrade the openai library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.