Improper error handling in parameters url, w, and q (unauthenticated and wallet-connected)
Malformed values supplied via the url, w, and q query parameters surfaced internal error details to the response, leaking implementation specifics useful to an attacker mapping the surface.
Description
The url, w, and q query parameters did not handle malformed input gracefully. Sending crafted values surfaced internal error messages (NestJS validation traces, stack-like output) in the response. Both unauthenticated and wallet-connected states were affected.
Impact
- Information disclosure: an attacker learns framework, library, and code-path details that accelerate reconnaissance.
- Lower threshold for further exploitation: error output frequently reveals route names, field names, and validation rules useful for crafting follow-on payloads.
Recommendation
Normalize all validation error responses to a single safe schema (status code, generic message, optional sanitized field identifier). Catch unexpected exceptions globally and return a controlled 500 with no leakage. Log full traces server-side, not into client responses.
All Your Base: Acknowledged. Zealynx: Acknowledged.