GHSA-wjmh-q7rf-cj53HighCVSS 8.6

keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces...

Published
August 30, 2026
Last Modified
September 2, 2026

🔗 CVE IDs covered (1)

📋 Description

keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic data. Attackers can access the /agent/pcap/keylog endpoint to retrieve NSS keylog lines and decrypt recorded TLS traffic, or invoke /agent/stop and /agent/storemocks to manipulate recording sessions.

🔗 References (10)