WhisperX tag archive

#data-leak

This page collects WhisperX intelligence signals tagged #data-leak. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (3)

The Lab · 2026-03-25 12:27:24 · GitHub Issues

1. Scikit-Learn Security Flaw: TfidfVectorizer Leaks Sensitive Training Data in Versions <=1.4.1

A critical data leakage vulnerability in the widely-used Python machine learning library scikit-learn has been patched, exposing sensitive information from training datasets. The flaw, tracked as CVE-2024-5206, was present in the TfidfVectorizer component in all versions up to and including 1.4.1.post1. The security fi...

The Lab · 2026-04-13 17:22:54 · GitHub Issues

2. Security Flaw in MosaicController: Bare Forbid() Leaks Data Existence to Anonymous Users

A critical data enumeration vulnerability has been identified in the `MosaicController.SaveMosaic` method. The flaw, located at line 192 of `Controllers/MosaicController.cs`, returns a bare `Forbid()` response when an `UnauthorizedAccessException` is thrown. This response is issued regardless of whether the caller is a...

The Lab · 2026-04-16 10:22:49 · GitHub Issues

3. GitHub Dependabot Alert: 'follow-redirects' Package Leaks Authorization Headers on Redirects

A critical security flaw has been flagged in the widely used `follow-redirects` npm package, posing a medium-severity risk of leaking sensitive authorization headers. The vulnerability triggers when the package automatically follows HTTP redirects to a different host, inadvertently exposing authentication tokens and cr...