Executive brief
The linqi application contains security flaws related to how it encrypts sensitive information. An attacker with local access to the system can bypass these protections to recover database credentials and other sensitive configuration details. This could lead to unauthorized access to corporate databases and a total compromise of the application's data integrity.
Technical details
The linqi application is vulnerable to two primary cryptographic weaknesses: the use of hardcoded cryptographic keys (CWE-321) and a cryptographically weak PRNG for Initialization Vector (IV) generation (CWE-338). Specifically, the application uses a limited ASCII charset and a weak algorithm to generate IVs for AES/CBC encryption. These flaws make known-plaintext attacks feasible. An attacker with local access and low privileges can exploit these vulnerabilities to decrypt obfuscated strings within configuration files, such as 'appsettings.json', potentially revealing plaintext database credentials and other sensitive ConnectionString values.
Affected products
- linqi linqi
Timeline
- 2026-06-05: disclosed
- 2026-06-05: advisory