Twelve logins to steal the keys. Math.random() signed the cookies.
By Lior AharonovFounder, 7IT Solutions ·
Rejetto HFS 3.0.0 through 3.2.0 derived its session-cookie signing key from Math.random() and leaked outputs of that same generator at login (CVE-2026-61500), as Horizon3.ai detailed on 30 September. SecurityWeek reports that on 2 October VulnCheck warned attackers had started targeting it. Version 3.2.1, out since 13 July, fixes it.
Horizon3.ai says about 12 leaked values rebuild the generator state, forge an admin cookie and reach code execution. The same mistake can hide in your own Node.js app: any session token, reset link or API key built with Math.random().
Upgrade any HFS server to 3.2.1 today. Then search your code for Math.random() near tokens, sessions or reset links and replace it with a cryptographic generator such as crypto.getRandomValues().
Math.random() is for shuffling a playlist. Never for the link that resets a password.
Lior Aharonov · my takeSources
- Horizon3.ai: CVE-2026-61500 Rejetto HFS disclosure horizon3.ai
- OSV: CVE-2026-61500 osv.dev
- SecurityWeek: Exploitation Hits Rejetto HFS Vulnerability Discovered by AI securityweek.com
Researched with AI tools; every fact is checked against the linked sources.