PT-2025-18911 · Flags+1 · Flags+1
Published
2025-05-02
·
Updated
2025-05-04
·
CVE-2025-46332
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Flags versions 3.2.0 and prior
@vercel/flags versions 3.1.1 and prior
Description
The issue allows for information disclosure, where a bad actor could gain access to a list of all feature flags exposed through the "flags discovery endpoint" (.well-known/vercel/flags), including the flag names, flag descriptions, available options and their labels, and default flag values. This can occur if a bad actor has detailed knowledge of the vulnerability.
Recommendations
For Flags versions 3.2.0 and prior, update to flags@4.0.0 to resolve the issue.
For @vercel/flags versions 3.1.1 and prior, migrate to flags@4.0.0 to resolve the issue.
As a temporary workaround, consider restricting access to the .well-known/vercel/flags endpoint until the update to flags@4.0.0 is applied.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Vercel/Flags
Flags