oauthopenid-connecttoken-leakagecredential-exposureagent-tokensloggingborutaASI08 · Cascading FailuresSurface: ProtocolPropagation: None
Boruta, an OAuth2/OIDC authorization server, logged sensitive credentials including access tokens, refresh tokens, ID tokens, and agent tokens in plaintext business event logs prior to version 0.10.0. Anyone with access to these logs, log aggregation pipelines, or the admin log viewer could extract valid tokens and reuse them for unauthorized access until expiration or revocation. This is a credential-hygiene vulnerability rather than a novel agent-specific attack, but it directly threatens agent-to-service authentication where 'agent tokens' are among the logged values.
Updated Sep 3, 2026 · CVSS 6.5