Junglewise Threat Intelligence

CVE-2020-26226: semantic-release secret disclosure in URI encoding

CVE-2020-26226 · Severity: low · CVSS 3.1 · Published 2020-11-18

Vendors: npm.

Executive brief

semantic-release is a Node.js library that automates version management and package publishing for JavaScript projects. A flaw in the secret masking mechanism can accidentally expose sensitive credentials (API keys, tokens, passwords) in build logs if those secrets contain characters that get URI-encoded, such as spaces or special symbols. An attacker with access to build logs could capture these disclosed secrets and use them to compromise the software supply chain.

Technical details

The vulnerability is a CWE-116 encoding error in semantic-release's secret masking logic. When secrets containing URI-encodable characters (spaces, ampersands, equals signs, etc.) are logged during the release process, the masking mechanism fails to recognize and redact them because the masking pattern does not account for URL-encoded variants of the secret. This affects versions before 17.2.3. An attacker with read access to build logs or CI/CD output can extract the exposed secrets. The fix, available in v17.2.3, corrects the pattern matching to handle both raw and URI-encoded forms of secrets.

Affected products

  • semantic-release semantic-release before 17.2.3

Timeline

  • 2020-11-18: disclosed
  • 2020-11-18: patched: Fixed in v17.2.3

References

Related threats