Junglewise Threat Intelligence

CVE-2025-1395: Codriapp HeyGarson sensitive information disclosure in error messages

CVE-2025-1395 · Severity: high · CVSS 8.2 · Published 2026-01-30

Executive brief

HeyGarson, a digital service platform, contains a security flaw where it reveals sensitive internal information through error messages. An unauthorized person could use this information to map out the application's internal structure and potentially gain deeper access to the system. The vendor has not responded to multiple attempts to coordinate a fix, meaning the software remains vulnerable.

Technical details

The HeyGarson application suffers from CWE-209 (Generation of Error Message Containing Sensitive Information). This vulnerability allows a remote, unauthenticated attacker to perform fuzzing against the application to trigger error states that reveal sensitive technical details. These details can be used for application mapping, potentially exposing internal paths, configuration details, or database structures. The vulnerability is present in versions up to 30012026. As of the latest advisory update, the vendor has not responded to disclosure attempts, and no patch has been confirmed.

Affected products

  • Codriapp Innovation and Software Technologies Inc. HeyGarson through 30012026

Timeline

  • 2026-01-30: disclosed
  • 2026-01-30: advisory: Initial advisory published by TR-CERT (USOM)

References