Early rate$2,400 of senior audit time for $500. Early members keep the rate as it climbs.$2,400 of senior audit time for $500See how →
F-2024-0003·information-disclosure

Improper error handling in parameters url, w, and q (unauthenticated and wallet-connected)

Acknowledgedpentestblackboxnestjs
TL;DR

Malformed values supplied via the url, w, and q query parameters surfaced internal error details to the response, leaking implementation specifics useful to an attacker mapping the surface.

Severity
MEDIUM
Impact
MEDIUM
Likelihood
MEDIUM
Method
MManual review
CAT.
Complexity
LOW
Exploitability
MEDIUM
02Section · Description

Description

The url, w, and q query parameters did not handle malformed input gracefully. Sending crafted values surfaced internal error messages (NestJS validation traces, stack-like output) in the response. Both unauthenticated and wallet-connected states were affected.

03Section · Impact

Impact

  • Information disclosure: an attacker learns framework, library, and code-path details that accelerate reconnaissance.
  • Lower threshold for further exploitation: error output frequently reveals route names, field names, and validation rules useful for crafting follow-on payloads.
04Section · Recommendation

Recommendation

Normalize all validation error responses to a single safe schema (status code, generic message, optional sanitized field identifier). Catch unexpected exceptions globally and return a controlled 500 with no leakage. Log full traces server-side, not into client responses.

All Your Base: Acknowledged. Zealynx: Acknowledged.

F-2024-0003