WhisperX tag archive

#information-disclosure

This page collects WhisperX intelligence signals tagged #information-disclosure. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (9)

The Lab · 2026-03-27 23:27:12 · GitHub Issues

1. GitHub Issue: Backend Error Handler Leaks `err.message` in Production, Exposing Internal Data

A critical information disclosure vulnerability has been identified in a backend application's global error handler. The middleware in `backend/src/middleware/auth.ts` is configured to always include the raw `err.message` in HTTP 500 responses, regardless of whether the application is running in a production environmen...

The Lab · 2026-03-29 01:26:50 · GitHub Issues

2. SECURITY: Critical Internal Error Leak Exposes Stack Traces & Infrastructure Details to HTTP Clients

A critical security flaw in multiple authentication handlers is leaking raw internal error messages, including stack traces and infrastructure details, directly to end-user HTTP clients. This exposure transforms routine server errors into a potential reconnaissance tool, revealing implementation specifics that could be...

The Lab · 2026-03-30 23:27:08 · GitHub Issues

3. Critical Security Gap in MCP Stdio Probe: Missing Tool-Risk, Info-Disclosure, and Internal-URI Scans

A significant security vulnerability has been identified in the `verifyMcpEndpointStdio` function within the codebase. This function, responsible for probing stdio-based Model Context Protocol (MCP) endpoints, lacks three critical security analysis passes that are standard in other probe paths, creating a dangerous inc...

The Lab · 2026-04-23 08:54:09 · GitHub Issues

4. SOAR MCP Integration Leaks Internal API URLs Through Error Messages, Aiding Reconnaissance

A security researcher has identified an information disclosure vulnerability in the SOAR (Security Orchestration, Automation and Response) MCP (Model Context Protocol) integration, where failed API calls return error messages containing full internal REST API URLs. The flaw exposes the SOAR platform's hostname and exac...

The Lab · 2026-04-23 09:54:15 · GitHub Issues

5. API Security Flaw Exposes Internal Invite UUIDs in Duplicate Invite Error Responses

A low-severity security vulnerability in the organization's invitation API allows internal invite identifiers to be exposed through error responses. When the system detects a duplicate invite attempt for an email address that already carries a pending invite within the same organization, the API returns the existing in...

The Lab · 2026-05-07 05:31:38 · GitHub Issues

6. WordPress Plugin Flaw Exposes Admin Security Notices to Any Subscriber-Level User

A critical access control failure in a WordPress plugin allows any authenticated user with Subscriber privileges to retrieve all admin-level notices, including those containing sensitive security information. The vulnerability, cataloged as [VULN-1-001], exposes plugin vulnerability alerts, failed login summaries, data...

The Lab · 2026-05-07 09:31:44 · GitHub Issues

7. Critical Information Disclosure Flaw Found in Apache Tomcat JsonAccessLogValve — Patch to 9.0.116 Required

A high-severity information disclosure vulnerability has been identified in Apache Tomcat's JsonAccessLogValve component, stemming from improper encoding of logged data. The flaw allows an attacker to potentially access sensitive information through manipulated HTTP requests that exploit how access logs are formatted a...

The Lab · 2026-05-07 23:31:39 · GitHub Issues

8. BentoML Patches Critical Symlink Traversal Flaw in Build Pipeline via Security Update to v1.4.39

BentoML has released version 1.4.39 as a security-patched update addressing a critical information disclosure vulnerability tracked as CVE-2026-40610 (GHSA-mcfx-4vc6-qgxv). The flaw resides in the `bentoml build` packaging workflow, where an attacker-controlled symlink traversal within the build context could enable un...

The Lab · 2026-05-13 07:48:29 · GitHub Issues

9. Appsmith OpenAPI Documentation Exposed to Unauthenticated Users Before Security Patch

Appsmith shipped a security fix addressing an information disclosure vulnerability that allowed any unauthenticated network user to access complete OpenAPI documentation for the platform. The flaw, tracked as GHSA-v6jh-fx3m-7xhw, earned a CVSS score of 5.3 (medium) and maps to CWE-200 (Exposure of Sensitive Information...