Vulnerability
Published 2026-09-30
Verified 2026-10-01

Rejetto HFS CVE-2026-61500 (CVSS 9.8): Math.random session-key forgery → admin RCE — Mythos agent write-up 30 Sep; patch 3.2.1

CVE-2026-61500 (VulnCheck/NVD; published mid-July 2026; GHSA-xxrm-3f86-v97j): Rejetto HTTP File Server (HFS) 3.0.0 through 3.2.0 derives the Koa/keygrip session-cookie signing key from non-cryptographic Math.random() and leaks outputs of the same V8 xorshift128+ PRNG to clients during loginSrp1. A remote attacker can collect a small number of login responses, reconstruct PRNG state, recover the signing key, forge an administrator session cookie, and reach RCE via the server_code / administrative API custom-endpoint path. CVSS 3.1 9.8 Critical and CVSS 4.0 9.3 Critical (VulnCheck via NVD/CVE.report). Fixed in HFS 3.2.1 (GitHub release / commit). UPDATE / desk hook 30 Sep 2026: Horizon3 Attack Research details how Anthropic Mythos (with a custom harness) rediscovered and fully chained the issue — including Z3-based PRNG state recovery and a working exploit path — as an agentic vulnerability-research case study. Primary: GHSA / rejetto v3.2.1; research wire: Horizon3 30 Sep.

Product
Rejetto HFS (HTTP File Server) 3.x
Versions
Affected: 3.0.0 through 3.2.0 (semver < 3.2.1). Fixed: 3.2.1+.
CVSS
(CVSS 3.1 Critical; VulnCheck) / 9.3 (CVSS 4.0 Critical; VulnCheck)
Exploited in Australia?
unknown
Patch to
Upgrade Rejetto HFS to 3.2.1 or later; do not expose admin/login interfaces to the internet on unpatched 3.0.0–3.2.0; rotate any sessions/secrets if a public HFS 3.x instance was reachable while vulnerable.

Primary: GitHub Advisory GHSA-xxrm-3f86-v97j — CVE-2026-61500 Rejetto HFS session forgery · Vendor: rejetto/hfs — v3.2.1 release (fixed) · CVE: CVE-2026-61500 · Horizon3 — Anthropic Mythos finds Rejetto HFS RCE (CVE-2026-61500) (30 Sep 2026)

vulnerabilities ai network