WhisperX tag archive

#CWE-532

This page collects WhisperX intelligence signals tagged #CWE-532. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (3)

The Lab · 2026-04-11 13:22:37 · GitHub Issues

1. Security Flaw: Database Migration Scripts Log Plaintext Passwords in Production Code

A critical security vulnerability has been identified in a production codebase, where database migration scripts are logging plaintext passwords directly to console output. The flaw, classified as a P0 high-severity issue, involves two specific functions within the `server/src/db/migrations.ts` file. On line 288, the `...

The Lab · 2026-04-12 21:22:34 · GitHub Issues

2. Logixlysia 6.3.1: Critical Info Disclosure - Full Error Objects Leak API Keys, Credentials to Logs

Logixlysia, a software platform, is exposing a critical information disclosure vulnerability that leaks sensitive data directly into its logs. The system's logging mechanism passes entire error objects to console output, log files, and external logging services without any sanitization or filtering. This flaw means any...