Improper Neutralization of Special Elements in Data Query Logic in Kiwi - #VU150956
Published: September 18, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper neutralization of special elements in data query logic in JSON-RPC API methods when processing calls that specify parameters by name. A remote user can send carefully crafted JSON-RPC requests to disclose sensitive information.
Sensitive fields are not directly returned in API responses but can be queried to deterministically discover their contents.