Junglewise Threat Intelligence

CVE-2026-81683: openssl-encrypt cleartext private key storage in SharedPreferences

CVE-2026-81683 · Severity: high · CVSS 8.4 · Published 2026-08-27

Technologies: openssl-encrypt (PyPI), Jahlives Openssl Encrypt. Vendors: PyPI, Jahlives.

Executive brief

openssl-encrypt is a Python library that provides encryption functionality and includes a desktop GUI for managing mTLS client certificates. Versions 1.4.8 and earlier store sensitive client private keys in plaintext in a world-readable file, allowing any local user with file system access to steal cryptographic credentials. This could enable attackers to impersonate the application for fraudulent mTLS connections or compromise downstream systems that rely on client certificate authentication.

Technical details

The vulnerability is a cleartext storage issue (CWE-312) in the desktop GUI's Settings screen, which accepts a combined PEM-formatted certificate and private key via a paste field. The entire PEM content, including the sensitive private key material, is stored unencrypted in SharedPreferences, a world-readable file with 0644 permissions. An attacker with local file system access can trivially read this file and extract the private key without authentication or user interaction. Version 1.4.9 remediates the issue by writing the PEM to a dedicated file with 0600 (owner-only) permissions and storing only the file path in SharedPreferences, while also providing a one-time migration to scrub existing cleartext values.

Affected products

  • openssl-encrypt openssl-encrypt <= 1.4.8

Timeline

  • 2026-08-12: disclosed: GitHub security advisory GHSA-r8gw-6hfj-98jw published
  • 2026-08-27: advisory: CVE-2026-81683 issued and published to NVD
  • 2026-08-27: patched: Version 1.4.9 released with fix

References

Related threats