Executive brief
Vantage6 is an open-source platform used for privacy-preserving data analysis. A security issue was identified where the server's default security keys (JWT secrets) are generated using a predictable method if not manually configured by the user. This could potentially allow an attacker to guess the security key, leading to unauthorized access or the ability to forge authentication tokens.
Technical details
The vantage6-server component uses Python's `uuid.uuid1()` to auto-generate a `JWT_SECRET_KEY` when one is not explicitly provided in the configuration. Because UUID1 is based on the host's MAC address and the current timestamp, it is not cryptographically secure and is partially predictable. An attacker who can predict the secret key could forge JSON Web Tokens (JWTs) to bypass authentication or escalate privileges. The vulnerability is classified as CWE-330 (Use of Insufficiently Random Values) and has been addressed in version 4.11.0 by switching to a more secure random generator.
Affected products
- vantage6 vantage6-server < 4.11.0
Timeline
- 2025-06-12: disclosed
- 2025-06-12: advisory
- 2025-06-12: patched: Fixed in version 4.11.0
References
- https://github.com/vantage6/vantage6/security/advisories/GHSA-m3mq-f375-5vgh
- https://github.com/vantage6/vantage6/commit/e39a262faf1cd4c554bf1b8e57eeea082da995c0
- https://github.com/pypa/advisory-database/tree/main/vulns/vantage6-server/PYSEC-2025-221.yaml
- https://api.github.com/repos/vantage6/vantage6/security-advisories/GHSA-m3mq-f375-5vgh