Junglewise Threat Intelligence

CVE-2026-81717: openssl_encrypt USB drive integrity bypass with fixed KDF salt

CVE-2026-81717 · Severity: medium · CVSS 4 · Published 2026-08-27

Technologies: openssl-encrypt (PyPI), Openssl Encrypt. Vendors: PyPI, Jahlives.

Executive brief

openssl_encrypt is a Python library that provides encryption features, including the ability to create secure portable USB drives. The library fails to detect files added to a USB drive and uses a hardcoded encryption salt, allowing an attacker with physical access to a USB drive to inject malicious files (including autorun payloads) undetected and potentially conduct offline password attacks against the drive encryption.

Technical details

The vulnerability consists of two related weaknesses in the portable USB drive feature. First, USBDriveCreator._verify_integrity_file only validates files listed in the stored manifest; files added to the drive after creation—including root-level autorun payloads—are not detected and integrity verification incorrectly passes. Second, the library uses a globally constant, hardcoded KDF salt (_LEGACY_FIXED_SALT) when deriving encryption keys for drives lacking a per-drive salt file, defeating precomputation resistance and enabling offline rainbow-table attacks. Both weaknesses assume the threat model where an attacker has physical write access to the removable USB drive. The fix, available in version 1.4.9, adds bidirectional integrity checks and generates unique per-drive salts for new drives while maintaining backward compatibility with legacy drives.

Affected products

  • openssl_encrypt openssl_encrypt before 1.4.9

Timeline

  • 2026-08-27: disclosed

References

Related threats