GHSA-x3r2-fj3r-g5mv

Suggest an improvement
Source
https://github.com/advisories/GHSA-x3r2-fj3r-g5mv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-x3r2-fj3r-g5mv/GHSA-x3r2-fj3r-g5mv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-x3r2-fj3r-g5mv
Aliases
Published
2026-05-12T15:09:08Z
Modified
2026-05-13T16:39:07Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
sealed-env: TOTP secret embedded in unseal token payload (enterprise mode)
Details

In sealed-env enterprise mode, versions 0.1.0-alpha.1 through 0.1.0-alpha.3 embedded the operator's literal TOTP secret in the JWS payload of every minted unseal token. JWS payload is base64-encoded JSON, NOT encrypted. Any party who could observe a minted token (CI build logs, container env dumps, kubectl describe pod, Sentry/Rollbar stack traces, log aggregators) could decode the payload and extract the TOTP secret in plaintext.

An attacker with (a) the master key (e.g. from a separate compromise such as a leaked CI secret) and (b) any single leaked unseal token can use the extracted TOTP secret to mint new valid unseal tokens for any future deploy indefinitely, breaking the second-factor property the library claimed.

Patched in 0.1.0-alpha.4 by replacing the embedded secret with a salt-bound HMAC derivative (enterprise_epoch = HMAC(totpSecret, salt || "epoch-v1")). The TOTP secret never leaves the operator's machine in the new design. The wire format change is incompatible — files sealed by affected versions must be re-sealed and the TOTP secret rotated. Full migration playbook in CHANGELOG.md.

Reported by an external reviewer who decoded the payload of a real minted token and confirmed bit-for-bit equality with the operator's .env.local TOTP secret.

Database specific
{
    "cwe_ids":  [
        "CWE-200",
        "CWE-522"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-05-12T15:09:08Z",
    "nvd_published_at":  "2026-05-12T14:17:08Z",
    "severity":  "CRITICAL"
}
References

Affected packages

npm / sealed-env

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.1.0-alpha.4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-x3r2-fj3r-g5mv/GHSA-x3r2-fj3r-g5mv.json"

Maven / io.github.davidalmeidac:sealed-env-core

Package

Name
io.github.davidalmeidac:sealed-env-core
View open source insights on deps.dev
Purl
pkg:maven/io.github.davidalmeidac/sealed-env-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.1.0-alpha.4

Affected versions

0.*
0.1.0-alpha.1
0.1.0-alpha.2
0.1.0-alpha.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-x3r2-fj3r-g5mv/GHSA-x3r2-fj3r-g5mv.json"