Server-generated Error Message Containing Sensitive Information Affecting @grpc/grpc-js package, versions <1.13.6>=1.14.0 <1.14.5


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.25% (15th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-GRPCGRPCJS-20251007
  • published29 Sept 2026
  • disclosed28 Sept 2026
  • creditSherry Zhou

Introduced: 28 Sep 2026

NewCVE-2026-101915  (opens in a new tab)
CWE-550  (opens in a new tab)

How to fix?

Upgrade @grpc/grpc-js to version 1.13.6, 1.14.5 or higher.

Overview

@grpc/grpc-js is a gRPC Library for Node

Affected versions of this package are vulnerable to Server-generated Error Message Containing Sensitive Information via the server-side RPC error handler in server.ts, which unconditionally includes the raw exception message in the gRPC status details transmitted to clients. When a server method handler throws an unhandled error, the error message - which may contain internal state, file paths, or other sensitive data - is sent to the remote caller as part of the UNKNOWN status response across all four RPC call types (unary, client-streaming, server-streaming, and bidirectional streaming).

CVSS Base Scores

version 4.0
version 3.1