Description
An information disclosure vulnerability affecting Flags SDK has been addressed. It impacted flags ≤3.2.0 and @vercel/flags ≤3.1.1 and in certain circumstances, allowed a bad actor with detailed knowledge of the vulnerability to list all flags returned by the flags discovery endpoint (.well-known/vercel/flags).
Recommendation
Update the flags package to the latest compatible version. Followings are version details:
- Affected version(s): <= 3.2.0
- Patched version(s): 4.0.0
References
Could your website be exposed too?
SmartScanner can check your website for Information Disclosure via Flags override link - flags and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Information Disclosure via Flags override link - CVE-2025-46332
- PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments - CVE-2026-45623
- Unauthenticated Disclosure of PSU HAX CMS Site Listings via haxPsuUsage API Endpoint - CVE-2025-48996
- Trix allows Cross-site Scripting via `javascript:` url in a link - CVE-2025-21610


