Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-27v8-7qqq-m35q

Опубликовано: 11 мая 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.7
CVSS3: 8.8

Описание

Crabbox before 0.9.0 contains an authentication bypass vulnerability in the coordinator user-token verification path where the verifyUserToken() function fails to reject payloads containing an admin claim, allowing attackers to escalate privileges. An attacker with access to the shared non-admin token can craft a user-token payload with admin: true, sign it using HMAC-SHA256, and present it to admin-only coordinator routes to gain full coordinator admin access including lease visibility, pool state management, and forced release operations.

Crabbox before 0.9.0 contains an authentication bypass vulnerability in the coordinator user-token verification path where the verifyUserToken() function fails to reject payloads containing an admin claim, allowing attackers to escalate privileges. An attacker with access to the shared non-admin token can craft a user-token payload with admin: true, sign it using HMAC-SHA256, and present it to admin-only coordinator routes to gain full coordinator admin access including lease visibility, pool state management, and forced release operations.

EPSS

Процентиль: 30%
0.00382
Низкий

7.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 8.8
nvd
3 месяца назад

Crabbox before 0.9.0 contains an authentication bypass vulnerability in the coordinator user-token verification path where the verifyUserToken() function fails to reject payloads containing an admin claim, allowing attackers to escalate privileges. An attacker with access to the shared non-admin token can craft a user-token payload with admin: true, sign it using HMAC-SHA256, and present it to admin-only coordinator routes to gain full coordinator admin access including lease visibility, pool state management, and forced release operations.

EPSS

Процентиль: 30%
0.00382
Низкий

7.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-290