Description
An information disclosure vulnerability affecting Flags SDK has been addressed. It impacted flags ≤3.2.0 and @vercel/flags ≤3.1.1 and in certain circumstances, allowed a bad actor with detailed knowledge of the vulnerability to list all flags returned by the flags discovery endpoint (.well-known/vercel/flags).
Recommendation
No fix is available yet. Followings are affected versions:
- <= 3.1.1
References
Related Issues
- Information Disclosure via Flags override link - flags - CVE-2025-46332
- PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments - CVE-2026-45623
- Unauthenticated Disclosure of PSU HAX CMS Site Listings via haxPsuUsage API Endpoint - CVE-2025-48996
- Trix allows Cross-site Scripting via `javascript:` url in a link - CVE-2025-21610
You might also like:
- Tags:
- npm
- @vercel/flags
Anything's wrong? Let us know Last updated on May 02, 2025


