{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/keploy-3.1.0---3.6.25/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:keploy:keploy:3.1.0:*:*:*:*:*:*:*","cpe:2.3:a:keploy:keploy:3.6.25:*:*:*:*:*:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Keploy (3.1.0 - 3.6.25)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Keploy"],"content_html":"\u003cp\u003eKeploy versions 3.1.0 through 3.6.25 include an insecure configuration where the agent control-plane HTTP server binds to all network interfaces (0.0.0.0) without requiring authentication. This exposure allows remote, unauthenticated attackers to interact with sensitive API endpoints. By accessing the /agent/pcap/keylog endpoint, an attacker can retrieve NSS keylog lines, which are sufficient to decrypt intercepted TLS traffic. Additionally, the vulnerability allows unauthorized access to management endpoints, specifically /agent/stop and /agent/storemocks, which can be leveraged to disrupt, terminate, or manipulate data recording sessions. This poses a significant risk to development and testing environments where Keploy is used to capture application traffic. Defenders should ensure Keploy instances are not exposed to untrusted networks and update to a patched version immediately.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the decryption of sensitive TLS traffic captured during session recording and the unauthorized control or corruption of testing data streams. This vulnerability impacts development, staging, and testing environments where Keploy is deployed, potentially compromising internal credentials, API keys, or proprietary data transmitted within the recorded sessions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Keploy to version 3.6.26 or later to enforce authentication on control-plane endpoints.\u003c/li\u003e\n\u003cli\u003eImplement network-level access control (firewall or security groups) to restrict access to the Keploy agent control-plane port to authorized management hosts only.\u003c/li\u003e\n\u003cli\u003eAudit existing recording sessions for signs of unauthorized manipulation or access to the /agent/pcap/keylog endpoint.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-30T15:11:19Z","date_published":"2026-08-30T15:11:19Z","id":"https://feed.craftedsignal.io/briefs/2026-08-keploy-auth-bypass/","summary":"Keploy versions 3.1.0 through 3.6.25 contain a vulnerability where the agent control-plane HTTP server binds to all interfaces without authentication, enabling unauthorized access to TLS session keys and recording management endpoints.","title":"Unauthenticated Access to Keploy Agent Control Plane","url":"https://feed.craftedsignal.io/briefs/2026-08-keploy-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Keploy (3.1.0 - 3.6.25)","version":"https://jsonfeed.org/version/1.1"}