THREAT OPS › Threat News › [GHSA] GHSA-5pq8-3ffp-7w5m (medium) — hashi-vault-js: Vault token and secret values exposed in thrown errors
[GHSA] GHSA-5pq8-3ffp-7w5m (medium) — hashi-vault-js: Vault token and secret values exposed in thrown errors
GHSA-5pq8-3ffp-7w5m Severity: medium CVE: CVE-2026-55102
hashi-vault-js: Vault token and secret values exposed in thrown errors
## Summary
Vault token and secret values are exposed in thrown errors when using `hashi-vault-js`.
## Details
Every API method in `Vault.js` executes `throw parseAxiosError(err)`, which returns the raw `AxiosError` untouched. That error carries the full Axios configu
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-55102cve
Original source: https://github.com/advisories/GHSA-5pq8-3ffp-7w5m