AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secrets
🔗 CVE IDs covered (1)
📋 Description
Summary
The telemetry subsystem embeds a hardcoded auth token ("secret") in the public source and transmits raw CLI arguments—including --secret, --jwt_secret, and --http_rpc_secret values—to a third-party telemetry endpoint.
Details
In telemetry/config.go line 12, var authToken = "secret" is committed in the public repository and used to authenticate to https://telemetry.anycable.io. In telemetry/telemetry.go, clusterFingerprint() (line 320) calls both anycableFileConfig(c.ConfigFilePath) (line 333), which reads the full TOML config file contents, and anycableCLIArgs() (line 402), which reads os.Args[1:] verbatim—including any --secret=..., --jwt_secret=..., --http_rpc_secret=... arguments. Both raw values are passed to generateDigest() (line 373), meaning the actual secret strings flow through the code path and are included in telemetry data sent to the third-party server. Since the hardcoded authToken = "secret" is public, any attacker who can perform DNS hijacking or is positioned on the network path can intercept and read the telemetry payload containing operator credentials.
PoC
- Read
telemetry/config.goin the public repo to findauthToken = "secret". - Set up a DNS spoof for
telemetry.anycable.iopointing to an attacker-controlled server. - Start anycable-go with
--secret=my-production-secret. - The server sends a POST to the attacker's endpoint with the telemetry JSON payload. The
clusterFingerprintfield contains data derived from rawos.Argsincluding--secret=my-production-secret.
Impact
In MITM/DNS-hijack scenarios, production secrets (JWT secrets, broadcast keys, RPC auth) are exposed to third parties. The hardcoded authToken = "secret" provides no protection since it is known to anyone reading the open-source code.
Fix
- Remove the hardcoded
authTokenfrom source; generate or require operator configuration at build time or deployment time. 2. RemoveanycableCLIArgs()from the fingerprint computation, or sanitize it to exclude values of secret-bearing flags before hashing. 3. Add a documented opt-out mechanism for telemetry.
🎯 Affected products1
- go/github.com/anycable/anycable:<= 1.6.14