From 77cfaa0870740a14513c3d6bc47804ca922a0e98 Mon Sep 17 00:00:00 2001 From: Ishaan Jaff Date: Tue, 3 Feb 2026 15:14:10 -0800 Subject: [PATCH] Potential fix for code scanning alert no. 4045: Information exposure through an exception Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> --- litellm/proxy/agent_endpoints/a2a_endpoints.py | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/litellm/proxy/agent_endpoints/a2a_endpoints.py b/litellm/proxy/agent_endpoints/a2a_endpoints.py index 338c054c177..cc66e21b9d0 100644 --- a/litellm/proxy/agent_endpoints/a2a_endpoints.py +++ b/litellm/proxy/agent_endpoints/a2a_endpoints.py @@ -102,12 +102,17 @@ async def _handle_stream_message( else: yield "data: " + json.dumps(chunk) + "\n\n" except Exception as e: - verbose_proxy_logger.exception(f"Error streaming A2A response: {e}") + # Log full exception details server-side for debugging + verbose_proxy_logger.exception("Error streaming A2A response") + # Return a generic error message to the client without exposing internal details yield "data: " + json.dumps( { "jsonrpc": "2.0", "id": request_id, - "error": {"code": -32603, "message": f"Streaming error: {str(e)}"}, + "error": { + "code": -32603, + "message": "Streaming error", + }, } ) + "\n\n"