Junglewise Threat Intelligence

CVE-2025-43866: Vantage6 Server insufficiently random JWT secret key

CVE-2025-43866 · Severity: medium · CVSS 4 · Published 2025-06-12

Technologies: vantage6-server (PyPI). Vendors: PyPI.

Executive brief

Vantage6 is an open-source platform used for privacy-preserving data analysis. A security issue was identified where the server's default security keys (JWT secrets) are generated using a predictable method if not manually configured by the user. This could potentially allow an attacker to guess the security key, leading to unauthorized access or the ability to forge authentication tokens.

Technical details

The vantage6-server component uses Python's `uuid.uuid1()` to auto-generate a `JWT_SECRET_KEY` when one is not explicitly provided in the configuration. Because UUID1 is based on the host's MAC address and the current timestamp, it is not cryptographically secure and is partially predictable. An attacker who can predict the secret key could forge JSON Web Tokens (JWTs) to bypass authentication or escalate privileges. The vulnerability is classified as CWE-330 (Use of Insufficiently Random Values) and has been addressed in version 4.11.0 by switching to a more secure random generator.

Affected products

  • vantage6 vantage6-server < 4.11.0

Timeline

  • 2025-06-12: disclosed
  • 2025-06-12: advisory
  • 2025-06-12: patched: Fixed in version 4.11.0

References

Related threats