T09 · Insecure Skill Coding Practices
- Location
lib/client/auth/AuthenticationService.ts:393- Finding
Authentication Credentials and TOTP Codes Exposed Through Debug Logging
- Content
View full analysis
= { username: email, password, trusted_device: true, supports_mfa: true, supports_email_otp: true, supports_recaptcha: true } if (mfaSecretKey) { const code = totp.authenticator.generate(mfaSecretKey) loginData.totp = code } ``` ### Technical Analysis The default console logger writes debug output to standard error when `MONARCH_LOG_LEVEL=debug`. Because the complete authentication request body is passed to the logger without redaction, debug output includes the plaintext account password and current MFA code. Standard error is frequently captured by CI systems, container runtimes, process supervisors, terminal recording software, or centralized logging platforms. This can expand access to authentication secrets beyond the process that legitimately needs them. Although the TOTP code is short-lived, the password remains reusable. A captured password and timely TOTP code can be used for immediate authentication. The disclosure also u ...[truncated 1242 chars]- Remediation
View remediation
