THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-5pq8-3ffp-7w5m (medium) — hashi-vault-js: Vault token and secret values exposed in thrown errors

[GHSA] GHSA-5pq8-3ffp-7w5m (medium) — hashi-vault-js: Vault token and secret values exposed in thrown errors

medgithub_advisoriesPublished 2026-08-13

GHSA-5pq8-3ffp-7w5m Severity: medium CVE: CVE-2026-55102

hashi-vault-js: Vault token and secret values exposed in thrown errors

## Summary

Vault token and secret values are exposed in thrown errors when using `hashi-vault-js`.

## Details

Every API method in `Vault.js` executes `throw parseAxiosError(err)`, which returns the raw `AxiosError` untouched. That error carries the full Axios configu

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-5pq8-3ffp-7w5m