CyberSecurityNews

Anthropic Mythos AI Finds Rejetto HFS Flaw That Lets Attackers Forge Admin Sessions and Execute Code


Anthropic’s Mythos AI has identified a critical vulnerability in Rejetto HTTP File Server that could allow remote attackers to forge administrator sessions and execute arbitrary code.

The issue, tracked as CVE-2026-61500, stems from predictable session-signing keys generated through JavaScript’s non-cryptographic Math.random() function.

Horizon3 made the finding after joining Anthropic’s Project Glasswing in July 2026, which uses the Mythos Preview model and industry partners to identify and fix critical and open-source software flaws. Anthropic says Mythos can autonomously find high-severity vulnerabilities and develop sophisticated exploit paths.

Rejetto HTTP File Server, commonly called HFS, is an open-source application for hosting and sharing files. The project has previously faced security issues, including CVE-2024-23692, an unauthenticated template-injection flaw that enabled remote code execution in older HFS releases.

The newly disclosed flaw affects the TypeScript-based HFS 3.x branch. HFS uses the Koa Node.js framework for session management. When the COOKIE_SIGN_KEYS configuration is not set, the application creates a signing key through randomId(30). That function relies on Math.random() rather than a cryptographically secure random-number generator.

Exploit in Action (source :horizon3.ai )

This creates a serious risk because Node.js’s V8 engine implements Math.random() using the xorshift128+ pseudo-random-number generator. The algorithm is fast but not designed for cryptographic security. An attacker can reconstruct its internal state if they obtain enough consecutive output values.

Anthropic Mythos AI Finds Rejetto HFS Flaw

Mythos reportedly identified that HFS leaked such outputs during its authentication process. The loginSrp1 endpoint generates a session identifier with Math.random() and stores it in a client-side session cookie.

Because the cookie is signed but not encrypted, an attacker can decode their own issued cookie and collect high-precision random values from the same V8 pseudo-random stream.

An attacker could repeatedly trigger the login process, recover the xorshift128+ internal state with a solver such as Z3, and step the state backward to derive the session-signing key created during server startup.

The recovered key could then be used to generate a valid session cookie claiming to belong to the HFS administrator account. The forged cookie can include fields that bypass session IP restrictions, such as allow_session_ip_change.

Once authenticated as an administrator, the attacker can abuse HFS administrative API functionality that supports custom endpoints and arbitrary JavaScript execution. This turns the authentication bypass into remote code execution on the affected server.

Horizon3 said Mythos not only found the weak PRNG use but also connected it to the exposed random values, developed a mathematical recovery approach, generated a working Z3-based proof of concept, and demonstrated arbitrary command execution.

The finding highlights a broader concern for defenders: AI-assisted vulnerability research may make complex flaws easier to weaponize. Bugs that once required cryptographic expertise, reverse engineering, and lengthy exploit development could become more accessible to threat actors as advanced models automate code analysis and exploit chaining.

HFS administrators should update to the vendor-fixed release when available, explicitly configure strong COOKIE_SIGN_KEYS, avoid relying on Math.random() for any security-sensitive value, restrict public access to administrative functions, and monitor logs for unusual authentication activity or unexpected custom endpoint creation.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC



Source link