Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-13288 | Information Disclosure via Flags override link |
Github GHSA |
GHSA-892p-pqrr-hxqr | Information Disclosure via Flags override link |
Fri, 02 May 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 02 May 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flags SDK is an open-source feature flags toolkit for Next.js and SvelteKit. Impacted versions include flags from 3.2.0 and prior and @vercel/flags from 3.1.1 and prior as certain circumstances allows a bad actor with detailed knowledge of the vulnerability to list all flags returned by the flags discovery endpoint (.well-known/vercel/flags). This vulnerability allows for information disclosure, where a bad actor could gain access to a list of all feature flags exposed through the flags discovery endpoint, including the flag names, flag descriptions, available options and their labels (e.g. true, false), and default flag values. This issue has been patched in flags@4.0.0, users of flags and @vercel/flags should also migrate to flags@4.0.0. | |
| Title | Information Disclosure via Flags override link | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-02T17:47:34.845Z
Reserved: 2025-04-22T22:41:54.911Z
Link: CVE-2025-46332
Updated: 2025-05-02T17:47:20.452Z
Status : Deferred
Published: 2025-05-02T17:15:52.947
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-46332
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA