Improper Neutralization of Special Elements in Data Query Logic in Kiwi - #VU150956

 

Improper Neutralization of Special Elements in Data Query Logic in Kiwi - #VU150956

Published: September 18, 2026


Vulnerability identifier: #VU150956
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-943
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper neutralization of special elements in data query logic in JSON-RPC API methods when processing calls that specify parameters by name. A remote user can send carefully crafted JSON-RPC requests to disclose sensitive information.

Sensitive fields are not directly returned in API responses but can be queried to deterministically discover their contents.


Affected software

Kiwi

Remediation

Install security update from vendor's website.

Kiwi - update to 16.4

External References

Related Security Bulletins