Junglewise Threat Intelligence

CVE-2025-46332: Vercel Flags information disclosure via flags discovery endpoint

CVE-2025-46332 · Severity: low · CVSS 3.1 · Published 2025-05-02

Vendors: npm, Vercel.

Executive brief

Vercel's Flags SDK, used to manage feature flags in web applications, contained a vulnerability that allowed attackers to retrieve a complete list of all feature flags and their configurations through an unprotected endpoint. An attacker with knowledge of the flaw could discover flag names, descriptions, default values, and available options—information that could reveal product roadmaps or internal feature states. Vercel has already mitigated the default endpoint on their platform, but self-hosted deployments and custom endpoint configurations remain at risk until upgraded.

Technical details

The vulnerability is an information disclosure flaw (CWE-200) in the flags discovery endpoint (/.well-known/vercel/flags) caused by an insufficient access control check in the verifyAccess function. The flawed endpoint allows unauthenticated, network-accessible requests to enumerate all flags with no authentication or user interaction required. An attacker with detailed knowledge of the vulnerability could list flag names, descriptions, options, and default values, but could not access flag providers, write to flags, or access additional customer data. The fix is available in flags@4.0.0 and @vercel/flags@4.0.0, where the verifyAccess function was patched. Vercel has automatically mitigated this on their platform via a network-level block, but custom implementations and Pages Router deployments must upgrade manually.

Affected products

  • Vercel Flags ≤3.2.0
  • Vercel @vercel/flags ≤3.1.1

Timeline

  • 2025-05-02: disclosed
  • 2025-05-02: patched: Fix available in flags@4.0.0 and @vercel/flags@4.0.0

References