While working on rivetkit project, I discovered a cache deception vulnerability in the better-call npm package (this dependency used by rivetkit). The issue stems from insufficient path sanitization, which allows attackers to craft deceptive requests that can bypass CDN rules and expose sensitive user data.
CVE Link
CVE Report