{"id":"CVE-2026-55102","aliases":["GHSA-5pq8-3ffp-7w5m"],"url":"https://o3.security/vulnerability/CVE-2026-55102","summary":"hashi-vault-js: Vault token and secret values exposed in thrown errors","details":"## Summary\n\nVault token and secret values are exposed in thrown errors when using `hashi-vault-js`.\n\n## Details\n\nEvery API method in `Vault.js` executes `throw parseAxiosError(err)`, which returns the raw `AxiosError` untouched. That error carries the full Axios configuration, including the `X-Vault-Token` header and the request body. Consuming applications that log caught errors (e.g., using `console.error`, `pino`, `winston`, Sentry, or APMs) inadvertently log the live Vault token in plaintext. Furthermore, write-path methods expose submitted passwords and secret values via `err.config.data`.\n\n## Impact\n\nWhen consuming applications log intercepted exceptions, sensitive credentials such as tokens, passwords, and secrets are unknowingly exposed to application logs, monitoring services, and APM systems via the raw `AxiosError`. This may lead to authorization bypass or unauthorized access to the underlying Vault instance.\n\n## Patches\n\nThis vulnerability should be addressed by redacting `err.config.headers['X-Vault-Token']` and `err.config.data` before re-throwing, or by throwing a purpose-built error containing only safe properties like status and message. Users should upgrade to a version that includes this fix.\n\n## Workarounds\n\nIf users cannot immediately update the library, they can mitigate this issue by capturing all exceptions thrown by `hashi-vault-js` and sanitizing or omitting the `err.config` object before passing the errors to logging utilities or crash reporters.\n\n## Acknowledgements\nhashi-vault-js would like to thank Sebastián Alba Vives for reporting this vulnerability.\n\n## Resources\n\n- [CWE-532: Insertion of Sensitive Information into Log File](https://cwe.mitre.org/data/definitions/532.html)\n- [CWE-209: Generation of Error Message Containing Sensitive Information](https://cwe.mitre.org/data/definitions/209.html)","published":"2026-09-14T16:58:00.208Z","modified":"2026-09-16T03:46:58.361129866Z","cvss":null,"epss":{"score":0.00114,"percentile":0.01655,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"hashi-vault-js","fixedVersion":"0.5.2"}],"fix":{"url":"https://github.com/kyndryl-open-source/hashi-vault-js/commit/ed0797a2d09c1fe0fd20764dde66cbc29241d9fb","label":"kyndryl-open-source/hashi-vault-js@ed0797a"},"references":[{"type":"WEB","url":"https://github.com/kyndryl-open-source/hashi-vault-js/releases/tag/v0.5.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55102.json"},{"type":"ADVISORY","url":"https://github.com/kyndryl-open-source/hashi-vault-js/security/advisories/GHSA-5pq8-3ffp-7w5m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55102"},{"type":"FIX","url":"https://github.com/kyndryl-open-source/hashi-vault-js/commit/ed0797a2d09c1fe0fd20764dde66cbc29241d9fb"},{"type":"FIX","url":"https://github.com/kyndryl-open-source/hashi-vault-js/pull/67"},{"type":"PACKAGE","url":"https://github.com/kyndryl-open-source/hashi-vault-js"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-16T03:46:58.361129866Z"}}