Wings Package Vulnerability: Sensitive Information Exposure Risk
An early warning has been issued regarding a vulnerability in the Wings package, where sensitive node configuration secrets may be exposed through the egg configuration-file templating engine.
What happened
The Wings package, specifically versions up to and including v1.12.2, appears to expose its entire daemon configuration to the egg configuration-file templating engine. This exposure allows a low-privileged user to potentially read sensitive information such as the node's daemon token and container-registry credentials. The issue is under investigation and has been tracked under the ID GHSA-PFVC-3P5H-X7H6. To mitigate this risk, it is recommended to upgrade to Wings v1.12.3. Professional software engineers using Wings in their projects should assess their exposure and consider upgrading as a precautionary measure. For more detailed information, consult the primary sources provided.
How 0Day mitigates this
wings is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.