Junglewise Threat Intelligence

CVE-2026-81697: openssl-encrypt KDF downgrade via CWD-relative configuration

CVE-2026-81697 · Severity: medium · CVSS 5.5 · Published 2026-08-27

Technologies: Openssl-Encrypt Openssl Encrypt.

Executive brief

openssl-encrypt is a Python library for encrypting files using strong key derivation and cryptographic hashing. A flaw in versions up to 1.4.8 causes the legacy GUI to read encryption settings from the current working directory instead of the user's home directory, allowing an attacker to plant a malicious configuration file that silently disables strong encryption protections. This enables offline brute-force attacks against encrypted files created during an affected GUI session.

Technical details

The vulnerability is a CWD-relative configuration file resolution flaw (CWE-426). The crypt_settings.py module defines CONFIG_FILE as an absolute path (~/.crypt_settings.json) at line 20 but reassigns it to a bare relative filename 'crypt_settings.json' at line 84, causing the legacy Tk GUI's SettingsTab to read and write configuration from the process launch directory. An attacker who plants a malicious crypt_settings.json with disabled memory-hard KDFs can reduce encryption to approximately one hash round. Because at least one hash iteration is present, the weak-KDF preflight check does not alert the user. The fix (version 1.4.9) removes the line-84 reassignment and adds a warning when weak KDF configurations are loaded. Attack vector is local; the attacker must be able to place a file in a directory where the application is launched. No network access required.

Affected products

  • openssl-encrypt openssl-encrypt <= 1.4.8

Timeline

  • 2026-08-12: disclosed: GitHub Security Advisory (GHSA-7j2v-g84w-m75v) published
  • 2026-08-27: advisory: NVD entry CVE-2026-81697 published
  • 2026: patched: Fixed in version 1.4.9

References