{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3acrawlabcrawlab/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:crawlab:crawlab:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-90945"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Crawlab (\u003c= 0.6.3)"],"_cs_severities":["critical"],"_cs_tags":["web-application","authentication-bypass","remote-code-execution"],"_cs_type":"advisory","_cs_vendors":["Crawlab"],"content_html":"\u003cp\u003eCrawlab versions up to and including 0.6.3 contain a critical vulnerability involving the use of a hard-coded HMAC-SHA256 secret for signing JSON Web Tokens (JWT). Because this secret cannot be overridden via configuration files or environment variables, it remains static across all installations. An unauthenticated attacker with knowledge of this hard-coded secret can construct forged JWTs with administrative claims. By presenting these forged tokens to the application's authentication middleware, an attacker gains unauthorized access to administrative APIs. These APIs include functionality that allows for the scheduling and execution of tasks on worker nodes, effectively leading to unauthorized remote code execution (RCE). This vulnerability poses a severe risk to any environment hosting Crawlab, as it bypasses all standard authentication controls.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full administrative compromise of the Crawlab platform. Attackers can gain unrestricted access to sensitive configuration data, control over scheduled web crawling tasks, and the ability to execute arbitrary code on infrastructure running Crawlab worker nodes. This impact is platform-wide, affecting all deployments using versions 0.6.3 or earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify and inventory all Crawlab instances currently running version 0.6.3 or earlier within the environment.\u003c/li\u003e\n\u003cli\u003ePrioritize the immediate upgrade of all identified Crawlab instances to the latest available patched version where the JWT secret implementation has been remediated.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious API requests carrying JWTs, specifically looking for anomalous administrative access patterns originating from unauthorized or external IP addresses.\u003c/li\u003e\n\u003cli\u003eEnforce network-level segmentation to restrict access to Crawlab administrative interfaces, ensuring they are not exposed to the public internet.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-14T19:35:11Z","date_published":"2026-09-14T19:35:11Z","id":"https://feed.craftedsignal.io/briefs/2026-09-crawlab-jwt-hardcoded-secret/","summary":"Crawlab versions 0.6.3 and earlier utilize a hard-coded HMAC-SHA256 secret for JWT signing, enabling unauthenticated attackers to forge administrative tokens and achieve remote code execution.","title":"Hard-coded JWT Secret in Crawlab Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-09-crawlab-jwt-hardcoded-secret/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:crawlab:crawlab:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}