GHSA-m3mq-f375-5vghLow

Vantage6 Server JWT secret not cryptographically secure

Published
June 12, 2025
Last Modified
June 8, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

The JWT secret key in the vantage6 server is auto-generated unless defined by the user. The auto-generated key is a UUID1, which is not cryptographically secure as it is predictable to some extent

Patches

No

Workarounds

You may define JWT secret key in the server configuration file

🎯 Affected products1

  • pip/vantage6-server:< 4.11.0

🔗 References (5)