Product
Keploy versions 3.1.0 through 3.6.25 contain a vulnerability where the agent control-plane HTTP server binds to all interfaces without authentication, enabling unauthorized access to TLS session keys and recording management endpoints.