CVE-2025-6624

LOW EPSS 4.7%
Published Jun 26, 20251y ago · Modified Jun 17, 20262w ago
1.2 CVSS 4.0
Low
Find Similar
Published Jun 26, 2025 1y ago
Last Modified Jun 17, 2026 2w ago

Description

Versions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through local Snyk CLI debug logs. Container Registry credentials provided via environment variables or command line arguments can be exposed when executing Snyk CLI in DEBUG or DEBUG/TRACE mode. The issue affects the following Snyk commands: 1. When snyk container test or snyk container monitor commands are run against a container registry, with debug mode enabled, the container registry credentials may be written into the local Snyk CLI debug log. This only happens with credentials specified in environment variables (SNYK_REGISTRY_USERNAME and SNYK_REGISTRY_PASSWORD), or in the CLI (--password/-p and --username/-u). 2. When snyk auth command is executed with debug mode enabled AND the log level is set to TRACE, the Snyk access / refresh credential tokens used to connect the CLI to Snyk may be written into the local CLI debug logs. 3. When snyk iac test is executed with a Remote IAC Custom rules bundle, debug mode enabled, AND the log level is set to TRACE, the docker registry token may be written into the local CLI debug logs.

CVSS Details

Base Score
1.2
Exploitability
Impact
Vector string
CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Local
Attack Complexity High
Privileges Required High
User Interaction P
Scope X

Threat Intelligence

EPSS Exploit Probability
4.7% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-532

Affected Products 1

VendorProductVersionRange
snyksnyk_cli* <1.1297.3

References 5

  • docs.snyk.io https://docs.snyk.io/snyk-cli/debugging-the-snyk-cli
    Technical Description
  • github.com https://github.com/snyk/cli/commit/38322f377da7e5f1391e1f641710be50989fa4df
    Patch
  • github.com https://github.com/snyk/cli/releases/tag/v1.1297.3
    Release Notes
  • github.com https://github.com/snyk/go-application-framework/commit/ca7ba7d72e68455afb466a7a47bb2c9aece86c18
    Patch
  • security.snyk.io https://security.snyk.io/vuln/SNYK-JS-SNYK-10497607
    Third Party Advisory

Remediation

  • github.com https://github.com/snyk/cli/commit/38322f377da7e5f1391e1f641710be50989fa4df
    Patch
  • github.com https://github.com/snyk/go-application-framework/commit/ca7ba7d72e68455afb466a7a47bb2c9aece86c18
    Patch