Executive brief
Kottster is a data integration and management platform used by developers to configure and deploy applications. The vulnerability allows attackers with access to a development instance to reinitialize the application, create an admin account, and execute arbitrary system commands. This impacts only development deployments, but poses a serious risk if development servers are exposed to untrusted networks or users.
Technical details
The vulnerability combines two flaws in Kottster's development mode: the initApp action lacks initialization state checks, permitting repeated calls that generate new root admin accounts and JWT tokens; and the installPackagesForDataSource action passes unescaped command arguments to system execution, enabling command injection. An unauthenticated attacker with network access to a running development instance can chain these issues to obtain admin credentials and execute arbitrary OS commands. The vulnerability requires local or network access to the development server and is not present in production deployments. Patches are available in @kottster/server v3.3.2 and @kottster/cli v3.3.2.
Affected products
- Kottster @kottster/server >=3.2.0, <3.3.2
- Kottster @kottster/cli >=3.2.0, <3.3.2
Timeline
- 2025-10-23: disclosed: Vulnerability disclosed via GHSA-j3w7-9qc3-g96p
- 2025-10-23: patched: Fixed in @kottster/server v3.3.2 and @kottster/cli v3.3.2