GSSA-2026-04-AMHCRRGITLAB-GSSA-2026-04-AMHCRRApril 25, 20269.8 Critical
Weak default fallback secrets allow JWT and CSRF token forgery in cobc-events
cobc-events <1.0.1 fell back to hard-coded development secrets when JWT_SECRET / SESSION_SECRET were unset, allowing forgery of session JWTs and CSRF HMAC tokens.
Affected (1)
- gelhaus-solutionscobc-events
- ≥ 0.0.0Fixed in 1.0.1
Mitigations
Workarounds
- Set `JWT_SECRET` and `SESSION_SECRET` to strong random values (at minimum 32 chars; e.g. `openssl rand -hex 48`) and restart the application before exposing it.
- Restrict access to the application origin via VPN or IP allowlist until the upgrade is applied.
Solutions
- Upgrade cobc-events to 1.0.1 or later.
- Rotate any tokens or sessions issued under the old default secrets after upgrade.
Exploits
- An attacker with knowledge of the default `dev-secret-change-me` JWT_SECRET can sign a token for any userId using the standard HS256 algorithm and present it as the `cobc_token` cookie to gain full session access. No interaction with the application is required.
Overview
cobc-events <1.0.1 fell back to hard-coded development secrets when JWT_SECRET / SESSION_SECRET were unset, allowing forgery of session JWTs and CSRF HMAC tokens.
Severity
CVSS v3
9.8 Critical
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
Weaknesses (3)
References (3)
- Patch in src/config/index.js (Patch)
- CWE-798: Use of Hard-coded Credentials (Third-party advisory)
- CWE-1188: Insecure Default Initialization (Third-party advisory)
Credits (5)
- Enno GelhausFinder · egelhaus@ennogelhaus.de
- Enno GelhausAnalyst · egelhaus@ennogelhaus.de
- Enno GelhausRemediation developer · egelhaus@ennogelhaus.de
- Enno GelhausRemediation reviewer · egelhaus@ennogelhaus.de
- Claude (Anthropic) — automated audit assistantTool · https://claude.com
Context
Impacts
Authentication bypass and full account takeover via forged JWTs
CAPEC-560CSRF protection bypass via forged HMAC tokens
CAPEC-62
Timeline
- 04/25/2026 00:00
Internal security audit started
- 04/25/2026 06:00
Vulnerability identified during audit
- 04/25/2026 12:00
Patch developed and merged to main
- 04/25/2026 14:00
cobc-events 1.0.1 released
- 04/25/2026 15:00
Advisory published