CVE-2026-5622Low· 3.7▾ SunlitA vulnerability was determined in hcengineering Huly Platform 0.7.382. Affected by this issue is some unknown functionality of the file foundations/core/packages/token/src/token.ts of the component JWT Token Handler. This manipulation of…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 20.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 24.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
A vulnerability was determined in hcengineering Huly Platform 0.7.382. Affected by this issue is some unknown functionality of the file foundations/core/packages/token/src/token.ts of the component JWT Token Handler. This manipulation of the argument SERVER_SECRET with the input secret causes use of hard-coded cryptographic key . The attack can be initiated remotely. The attack is considered to have high complexity. The exploitation is known to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-90510High· 8.3A security vulnerability has been detected in dromara orion-visor up to 2.5.7
CVE-2026-86241Medium· 4.3A weakness has been identified in liufee FeehiCMS up to 2.1.1
CVE-2025-13877Medium· 5.6A vulnerability was detected in nocobase up to 1.9.4/2.0.0-alpha.37
CVE-2025-6666Low· 2.0A vulnerability was determined in motogadget mo.lock Ignition Lock up to 20251125
CVE-2026-5527Medium· 5.3A weakness has been identified in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53
CVE-2026-8243Medium· 5.3A vulnerability was determined in Industrial Application Software IAS Canias ERP 8.03