Executive brief
ZPan is a lightweight file hosting platform that integrates with S3-compatible storage. A security flaw in its authentication system uses a hard-coded password for certain token operations, which could allow an attacker to potentially gain unauthorized access to user data or system functions. While the attack is complex to execute, it poses a risk to the confidentiality of files managed by the platform.
Technical details
A Use of Hard-coded Password (CWE-259) vulnerability exists in saltbo ZPan versions prior to 1.6.6. The flaw is located in the NewToken function within zpan/internal/app/service/token.go, which handles JSON Web Tokens. Specifically, the implementation utilizes a hard-coded value ('123') during token generation or validation. A remote attacker could potentially exploit this to bypass authentication or forge tokens, though the attack complexity is rated as high due to the specific conditions required for successful exploitation. The issue was addressed in version 1.6.6 by removing the hard-coded credential.
Affected products
- saltbo ZPan < 1.6.6
Timeline
- 2025-07-11: disclosed
- 2025-07-11: advisory
- 2026-07-16: patched: GitHub Advisory reviewed and updated with patch information.