Information Disclosure in Vaadin Maven and Gradle Plugins by Vaadin
CVE-2026-7860
1.6LOW
What is CVE-2026-7860?
An information disclosure vulnerability exists in the Vaadin Maven and Gradle plugins that can expose sensitive environment variables in clear text if a frontend build fails. This occurs when the build process exits with a non-zero status, revealing secrets, including credentials, within CI logs and archived artifacts. To mitigate this risk, users are advised to upgrade to the specified patched versions to secure their build environments.
Affected Version(s)
flow 23.0.0 <= 23.6.10
flow 24.0.0 <= 24.9.17
flow 24.10.0 <= 24.10.3
