Skip to finding
important · RCE

Active exploitation now makes HFS’s predictable session-signing keys an unauthenticated server-execution path.

Affects

Rejetto HFS, a self-hosted HTTP file server for Windows, Linux, macOS, FreeBSD and Android.

The attacker needs a network-reachable HFS 3.x server and a login-enabled username available through the documented enumeration oracle.

Detail and 3 sources

Consecutive Math.random outputs reveal recoverable xorshift128+ state, which yields the startup signing key used to forge an administrator session.

HFS 3.2.1 is published as the fixed release.

Today’s change is the complete root cause and execution chain, accompanied by observed exploitation.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, October 5, 2026