Full Report
Exploitation attempts came from China-hosted IP, VulnCheck researcher says
Analysis Summary
# Vulnerability: Critical Authentication Bypass in Rejetto HTTP File Server (HFS)
## CVE Details
- **CVE ID:** CVE-2026-61500
- **CVSS Score:** Critical (Exact numerical score not specified in text, but described as "critical authentication-bypass bug")
- **CWE:** CWE-330: Use of Insufficiently Random Values / CWE-287: Improper Authentication
## Affected Systems
- **Products:** Rejetto HTTP File Server (HFS)
- **Versions:** Versions prior to v3.2.1
- **Configurations:** Systems utilizing HFS where the `Math.random()` output is leaked through application code paths, allowing for session signing key derivation.
## Vulnerability Description
The flaw involves a cryptographic misstep in how HFS authenticates users. The application generates a random value using the V8 engine’s `Math.random()` function and passes it to the Koa (Node.js) web framework. Koa then uses this value via the `keygrip` library to sign session cookies.
Mythos (Anthropic’s security model) identified that:
1. The `xorshift128+` algorithm used by the V8 PRNG is fully reversible.
2. The application leaked raw `Math.random()` outputs through a separate code path.
3. By using an SMT solver (Z3), an attacker can recover the internal state of the PRNG from the leaked outputs, derive the session signing key, and forge valid administrative session cookies.
## Exploitation
- **Status:** **Exploited in the Wild.** Initially detected by VulnCheck "canaries."
- **Complexity:** Low to Medium (once the PRNG state recovery method is weaponized).
- **Attack Vector:** Network (Remote)
- **PoC Availability:** Yes. Horizon3 researcher Zach Hanley has published a technical write-up and a video demonstrating Remote Code Execution (RCE).
## Impact
- **Confidentiality:** High (Full admin access to the file server)
- **Integrity:** High (Ability to modify files and execute arbitrary code)
- **Availability:** High (Potential for full system takeover or service disruption)
## Remediation
### Patches
- Update Rejetto HFS to **version v3.2.1** or later immediately.
- Source: hxxps[://]github[.]com/rejetto/hfs/releases/tag/v3.2.1
### Workarounds
- No specific software workarounds provided; immediate patching is the recommended course of action given the active exploitation.
- Restrict access to the HFS interface to trusted IP addresses via firewall/ACLs.
## Detection
- **Indicators of Compromise (IoCs):**
- Observed attacking IP (China-hosted): [Check logs for high-volume attempts or unusual session cookie patterns].
- Observed proxy IPs (US-based): `173.239.211[.]248` and `173.239.211[.]249`.
- **Detection Methods:** Monitor for unauthorized administrative logins and inspect web server logs for exploitation attempts targeting the identified PRNG leak code paths.
## References
- **Vendor Release:** hxxps[://]github[.]com/rejetto/hfs/releases/tag/v3.2.1
- **Horizon3 Research:** hxxps[://]horizon3[.]ai/attack-research/disclosures/anthropic-mythos-rejetto-hfs-rce/
- **Exploit Video:** hxxps[://]vimeo[.]com/1231352419?fl=pl&fe=vl
- **VulnCheck Tracker:** hxxps[://]github[.]com/patrickmgarrity/Anthropic-Credited-CVEs