Executive brief
A popular Go-based web application template contains a hardcoded security key used to sign login tokens. Because this key is publicly known, an attacker can create their own valid login tokens to impersonate any user, including administrators. This allows unauthorized access to sensitive data and the ability to modify system information without a valid password.
Technical details
The application utilizes a hardcoded JWT signing secret ("random") defined in both the template environment file and as a programmatic fallback in the server configuration. While a mitigation was present to replace the string "random" with a generated key, the replacement was non-persistent (stored only in memory), causing session loss on restarts, and failed to check for other common weak secrets. An unauthenticated remote attacker can use the known secret to sign forged HS256 JWT tokens with arbitrary claims, such as admin roles. This results in a complete authentication bypass across all protected API endpoints. The vulnerability is addressed in PR #31 by implementing a blocklist of weak secrets and requiring a minimum secret length.
Affected products
- dhax go-base < 0.0.0-20260517152733-cc82b9740fa6
Timeline
- 2026-05-17: patched: Fix merged in PR #31
- 2026-05-20: disclosed: Initial advisory publication
- 2026-06-10: advisory: Updated advisory published on GitHub