UNKNOWN PyPI

Vantage6 Server JWT secret not cryptographically secure

GHSA-m3mq-f375-5vgh · CVE-2025-43866 · PYSEC-2025-221

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

The JWT secret key in the vantage6 server is auto-generated unless defined by the user. The auto-generated key is a UUID1, which is not cryptographically secure as it is predictable to some extent

Patches

No

Workarounds

You may define JWT secret key in the server configuration file

Ready to move

Start Securing

Free, no credit card | First findings in minutes