Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
- ID
- 31840
- Status
- summarized
- Published
- 05 Oct 2026, 4:09 PM
- Fetched
- 05 Oct 2026, 7:15 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/10/attackers-target-rejetto-hfs-flaw-that.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 6.0
- Created
- 05 Oct 2026, 7:17 PM
- Tags
- Audience
- developersvibe_codersai_ml_learners
What happened
CVE-2026-61500 (CVSS 9.3) affects Rejetto HFS 3.0.0 through 3.2.0: the server derived its session-cookie signing key from JavaScript's non-cryptographic Math.random() and leaked outputs of the same V8 PRNG to unauthenticated clients during the SRP login handshake, letting an attacker reconstruct the generator state, recover the signing key, forge an admin cookie, and reach remote code execution through the server_code configuration feature. A patch shipped in July 2026 as version 3.2.1, but a public Python PoC by Alejandro Ramos (aramosf) landed in late September, and VulnCheck's Patrick Garrity says exploitation attempts were detected on October 1, 2026 — one day after Horizon3.ai published more detail. Horizon3.ai researcher Zach Hanley stated that Anthropic's Mythos model was used to discover the flaw.
Why it matters
The direct action item is narrow: if you self-host Rejetto HFS, anything in 3.0.0–3.2.0 is exploitable in the wild as of October 1, 2026 and needs to be on 3.2.1. The broader lesson is worth more — session-signing keys and tokens generated with Math.random() (or any non-CSPRNG) are recoverable from observed outputs, and this is exactly the pattern AI coding assistants emit by default when you ask for a session or token helper, so check any JS/Node auth code you or a vibe-coded tool generated.
Discussion angle
An AI model reportedly found this bug end-to-end — from unauthenticated PRNG output to admin cookie to RCE. Is 'have a model read the auth code' now a realistic part of a pre-ship checklist for small teams, or does it mostly surface the same Math.random()-as-crypto mistakes a careful reviewer would catch?