Loading HuntDB...

GHSA-6xhf-x49c-m5m6

GitHub Security Advisory

Github Token Leak in aegir

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Affected versions of `aegir` bundle and publish the current users github token to npm when `aegir-release` is executed.

## Recommendation

Update to version 12.0.8 or later.

If you used this module to do a release for your project you should invalidate the GitHub tokens that were leaked.

Affected Packages

npm aegir
Affected versions: 12.0.0 (fixed in 12.0.8)

Related CVEs

Key Information

GHSA ID
GHSA-6xhf-x49c-m5m6
Published
July 24, 2018 8:04 PM
Last Modified
August 31, 2020 6:27 PM
CVSS Score
7.5 /10
Primary Ecosystem
npm
Primary Package
aegir
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 30, 2025 6:32 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.