CRITICAL
avitorio
CVE published 2026-07-30
CVE-2026-52539
Outstatic CMS version 2.1.9 and earlier contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to a default value visible in the source code repository. This allows unauthenticated remote attackers to forge JWT session tokens with arbitrary user data and full administrative permissions. The hardcoded secret is a critical security risk [truncated]