nostr-sdk is vulnerable to Insertion of Sensitive Information into Log File
45
Medium Risk
Several NIP-46 remote-signer types expose their underlying debug formatting through the generated bindings, even though their fields hold connection credentials and request parameters. Reading repr() of these objects, or letting them reach logs, tracing spans, or error reports, exposes the NIP-46 connection secret and request contents. Anyone able to read those outputs can recover the credential and impersonate the signer connection. The fix redacts credentials and plaintext fields in the debug output while preserving non-sensitive structure.
You are affected if you are using a version that falls within the vulnerable range and your application includes the repr() of NIP-46 connect types in logs, tracing, or error reports.
nostr-sdk is vulnerable to Insertion of Sensitive Information into Log File in versions 0.32.1 - 0.44.7.
Upgrade the nostr-sdk library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant