Skip to finding
interesting · Edge — RCE

Public code connects HFS administrator-session forgery to server-side code execution.

Affects

Rejetto HFS 3.x, a cross-platform self-hosted HTTP file-sharing server.

Unauthenticated login responses expose consecutive output from the generator used to derive HFS’s cookie-signing key. Recovering that state permits a forged administrator session, after which set_config and server_code execute JavaScript in the server context.

Detail and 6 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, October 6, 2026