Executive brief
HeyGarson, a digital service platform, contains a security flaw where it reveals sensitive internal information through error messages. An unauthorized person could use this information to map out the application's internal structure and potentially gain deeper access to the system. The vendor has not responded to multiple attempts to coordinate a fix, meaning the software remains vulnerable.
Technical details
The HeyGarson application suffers from CWE-209 (Generation of Error Message Containing Sensitive Information). This vulnerability allows a remote, unauthenticated attacker to perform fuzzing against the application to trigger error states that reveal sensitive technical details. These details can be used for application mapping, potentially exposing internal paths, configuration details, or database structures. The vulnerability is present in versions up to 30012026. As of the latest advisory update, the vendor has not responded to disclosure attempts, and no patch has been confirmed.
Affected products
- Codriapp Innovation and Software Technologies Inc. HeyGarson through 30012026
Timeline
- 2026-01-30: disclosed
- 2026-01-30: advisory: Initial advisory published by TR-CERT (USOM)