CVE-2023-6460: Google Cloud Firestore

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

A potential logging of the firestore key via logging within nodejs-firestore exists - Developers who were logging objects through this._settings would be logging the firestore key as well potentially exposing it to anyone with logs read access. We recommend upgrading to version 6.1.0 to avoid this issue

Affected products

  • Google Cloud Firestore: before 6.1.0 (fixed in 6.1.0)

Published 2023-12-04. Last modified 2026-06-17.