PatchSiren

avitorio CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL avitorio CVE published 2026-07-30

CVE-2026-52539

Outstatic CMS version 2.1.9 and earlier contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to a default value visible in the source code repository. This allows unauthenticated remote attackers to forge JWT session tokens with arbitrary user data and full administrative permissions. The hardcoded secret is a critical security risk [truncated]