Fix stack trace leaked in error response in Elysia
Returning an error's `.stack` to the client exposes absolute file paths, dependency versions, and internal call structure. Attackers use it to map the application and to fingerprint vulnerable dependency versions. Log the stack server-side and return a generic message.
high likely Elysia CWE-209 / OWASP A05:2021
The vulnerable pattern in Elysia
This finding comes from the Elysia fixture in the owlwarden test suite. Stack traces expose absolute file paths, dependency versions, and internal call structure - enough to fingerprint the stack and locate other weaknesses.
The corrected handler
Use `onError` so every route answers the same way, and keep the detail in the log.
app.onError(({ error, set }) => {
console.error(error)
set.status = 500
return { error: 'Internal Server Error' }
})
If you are not using Elysia
Log the error server-side and return a generic message to the client.
Check your own repository
npx owlwarden scan
npx owlwarden explain stack-trace-leak
Runs on your machine. No account, no telemetry, no network unless you ask. In CI, SARIF uploads to code scanning and the exit code is the gate.
Other Elysia checks
Rules with a tested Elysia example.
- cors-permissive medium Cross-origin policy accepts any origin
- hardcoded-secret high Credential hardcoded in source
- insecure-cookie medium Cookie set without its protective attributes
- install-lifecycle-script medium Package declares an install-time script
- open-redirect medium Redirect target comes from the caller
- security-headers-missing medium Security headers are not configured
- sensitive-data-logged medium Sensitive data written to a log
- sql-injection high SQL query built by string interpolation
- ssrf high Server fetches a URL the caller controls
- weak-crypto high Broken cryptographic primitive protecting a secret
stack-trace-leak for every framework / All rules / owlwarden