traQ Messenger Application Sensitive Information Logging Vulnerability

Vulnerability

A vulnerability in the traQ messenger application, prior to version 3.25.0, allows for the unintentional logging of sensitive information, such as OAuth tokens, in SQL error logs. This occurs when an error is triggered during SQL query execution, which could be exploited by an attacker with access to the log files. The vulnerability has been patched in version 3.25.0.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information, including OAuth tokens, which could be misused if logged before the patch was applied.

Remediation

Users are advised to upgrade to traQ version 3.25.0 or later. If an immediate upgrade is not possible, review and restrict access permissions for SQL error logs to prevent unauthorized users from viewing them.

Added: Aug 26, 2025, 4:18 PM
Updated: Aug 26, 2025, 4:18 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.5
remediation
0.0
relevance
0.4
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.