Executive brief
openssl-encrypt is a Python library for encrypting files using strong key derivation and cryptographic hashing. A flaw in versions up to 1.4.8 causes the legacy GUI to read encryption settings from the current working directory instead of the user's home directory, allowing an attacker to plant a malicious configuration file that silently disables strong encryption protections. This enables offline brute-force attacks against encrypted files created during an affected GUI session.
Technical details
The vulnerability is a CWD-relative configuration file resolution flaw (CWE-426). The crypt_settings.py module defines CONFIG_FILE as an absolute path (~/.crypt_settings.json) at line 20 but reassigns it to a bare relative filename 'crypt_settings.json' at line 84, causing the legacy Tk GUI's SettingsTab to read and write configuration from the process launch directory. An attacker who plants a malicious crypt_settings.json with disabled memory-hard KDFs can reduce encryption to approximately one hash round. Because at least one hash iteration is present, the weak-KDF preflight check does not alert the user. The fix (version 1.4.9) removes the line-84 reassignment and adds a warning when weak KDF configurations are loaded. Attack vector is local; the attacker must be able to place a file in a directory where the application is launched. No network access required.
Affected products
- openssl-encrypt openssl-encrypt <= 1.4.8
Timeline
- 2026-08-12: disclosed: GitHub Security Advisory (GHSA-7j2v-g84w-m75v) published
- 2026-08-27: advisory: NVD entry CVE-2026-81697 published
- 2026: patched: Fixed in version 1.4.9