Executive brief
PKP pkp-lib is a library used by scholarly publishing applications (OJS, OMP, OPS) to manage API authentication. A weakness in the API key generation function uses insufficiently random data (based on the current time), allowing an attacker to predict or brute-force API keys and gain unauthorized access to application functionality.
Technical details
The vulnerability is a weak randomness issue in the setData function of classes/user/form/APIProfileForm.php, specifically in API key generation. The vulnerable code uses sha1(time()) to generate API keys, which provides only time-based entropy and is cryptographically weak. An attacker with network access can predict or enumerate API keys by testing values derived from recent timestamps. The attack is characterized as having high complexity and difficult exploitability. The fix (commit 529b5df) increases API key entropy by using stronger randomness. Patching is recommended to resolve this issue.
Affected products
- PKP pkp-lib 3.3.0, 3.4.0, 3.5.0
Timeline
- 2026-08-15: disclosed
- 2026-08-15: patched: commit 529b5df878e571ccc727647f7748eafc1466b041