← Back to all posts
News

Hackers Exploit Mythos-Found Rejetto HFS Flaw a Day After Horizon3 Publishes the Chain

October 4, 2026 · 17:04 UTC · News
Hackers Exploit Mythos-Found Rejetto HFS Flaw a Day After Horizon3 Publishes the Chain

TL;DR

On Wednesday, September 30, Horizon3.ai researcher Zach Hanley published a full technical writeup of CVE-2026-61500, an unauthenticated admin-session forgery in Rejetto HTTP File Server (HFS) that ends in remote code execution. The bug was found by Anthropic's Mythos model inside Project Glasswing, and it is a genuinely clever chain: a non-cryptographic PRNG, plus a code path that leaks its raw outputs, plus an SMT solver to run the generator backwards. By Thursday evening VulnCheck's canaries caught an attacker in China using it against real hosts. The fix, HFS 3.2.1, had been out since July 13. If you run HFS 3.0.0 through 3.2.0 on anything reachable, stop reading and upgrade.


What actually happened, in order

The timeline is the story, because the patch was never the problem. HFS 3.2.1 shipped on July 13 with release notes crediting "Zach Hanley from Horizon3.ai, along with Claude and Anthropic Research" for multiple vulnerabilities that could grant administrative access. VulnCheck's advisory, dated the same day, rated it CVSS 4.0 9.3 (critical) under CWE-338, the weak-PRNG category.

Then nothing visible happened for 79 days. On September 30, Horizon3 published the exploitation details. According to The Register, VulnCheck detected exploitation Thursday evening, and on Friday saw four more hits from two US-based IP addresses on the same subnet (173.239.211.248 and .249), which look like proxies.

"Our canaries detected an actor in China targeting real vulnerable hosts in the US." (Patrick Garrity, VulnCheck, to The Register)
CVE-2026-61500, fix to first exploitation Jul 13HFS 3.2.1 fix Sep 30writeup public Oct 1exploited Oct 2+4 hits 79 days quiet ~1 day
The patch sat unexploited for 79 days. The exploit recipe was weaponized in about one.

The chain Mythos found

HFS 3 is a Node.js app built on Koa. It derives the signing key for its koa-session cookies at process startup with a 30-character random ID built from three consecutive calls to Math.random(). In V8, Math.random() is xorshift128+, which is fast, statistically fine, and not remotely a CSPRNG. Its operations are fully reversible.

That alone is a code smell, not an exploit. The second half is what made it one: the unauthenticated loginSrp1 endpoint stored a full-precision Math.random() value in the session as a login ID. Koa session cookies are base64 JSON that is signed but not encrypted, so the client can simply decode its own cookie and read the exact 52-bit double the server generated.

Think of it like a casino dealer who shuffles with a known machine and then hands every player a card from the top of the deck face up. With enough of those cards, you can work out the machine's starting position and, from there, the cards it dealt before you sat down, including the one that became the house key.

Horizon3's exploit samples the leaking endpoint 12 times (in theory roughly 3 to 5 consecutive doubles are enough), feeds the observations to Microsoft's Z3 SMT solver to recover the xorshift128+ internal state, steps the generator backwards to the startup outputs, rebuilds the signing key, and forges a cookie for admin. From there, RCE is a feature, not a bug: HFS's admin side lets you define custom server code, which runs arbitrary JavaScript on the host.

loginSrp1leaks doubles Z3 solvesPRNG state step back tostartup key forgeadmin cookie customJS = RCE no password at any step
Two separately harmless-looking facts, a weak PRNG and a leaked output, chained into unauthenticated RCE.

Why the Mythos part matters

Horizon3 joined Project Glasswing in July and runs Mythos through a harness that spawns many specialized agents in parallel, each hunting one vulnerability class. The cryptographic-weakness agent produced this chain without follow-up prompting, according to the writeup.

"What makes this impressive is that Mythos didn't just flag the insecure PRNG in isolation, it simultaneously identified that the application leaked raw Math.random() outputs through a separate code path, recognized those two facts as a chain, and determined the leak produced exactly the observations needed to make state recovery feasible." (Zach Hanley, Horizon3)

Static analyzers have flagged Math.random() in security contexts for years, and most teams triage those warnings as noise because "it is just a session ID." The new thing is a tool that also finds the oracle, proves the state space is small, and writes the solver. Horizon3 itself notes that its researchers rarely pursue weaponizing cryptographic flaws. The model did not share that reluctance.

Exploited CVEs are still rare. This one was easy.

VulnCheck's Patrick Garrity maintains a public tracker of Anthropic-credited CVEs. At the time of writing it lists 300 CVEs, plus 128 fixed findings without a CVE and 243 findings Anthropic withdrew. Only two are marked exploited in the wild in VulnCheck's KEV: CVE-2026-61500 and a Ghost CMS bug from February.

Anthropic-credited CVEs by CVSS (tracker, Oct 4) Critical39 High141 Medium81 Low/none39 Exploited2 of 300 (VulnCheck KEV)
Hundreds of AI-found CVEs, two known exploited. The difference here was a public, copyable recipe.

Low exploitation so far is good news, and also a little misleading. HFS is a hobbyist and small-office file server that often sits directly on the internet with nobody watching its version number. Its 2.x line has a long history in exactly these attack logs. A step-by-step chain against that kind of target is an invitation, and attackers RSVPed within a day.

What you should do

  • Upgrade HFS. Anything from 3.0.0 through 3.2.0 is vulnerable; 3.2.1 or later fixes it. The current stable line is 3.3.x. If you cannot upgrade right now, take it off the public internet.
  • Assume compromise on exposed instances. A forged admin cookie leaves no failed-login trail. Check the admin config for custom server code you did not write, and rotate anything the box could reach.
  • Grep your own Node code. Any Math.random() feeding a token, key, nonce, or session ID should be crypto.randomBytes or crypto.randomUUID. Signed-but-not-encrypted cookies are readable by the client, so treat everything you put in them as public.
  • Re-read your "won't fix, low risk" backlog. Findings that were only dangerous in combination are exactly what agent harnesses now connect.

The disclosure question nobody has solved

This is not a case of a vendor sitting on a fix. Rejetto patched, VulnCheck published an advisory the same day, and Horizon3 waited more than two and a half months before releasing details. That is a textbook responsible-disclosure gap. The problem is that patch adoption for self-hosted hobby servers does not run on a 79-day clock, and the writeup turned a CWE label into a recipe.

Expect this pattern to repeat as the Glasswing pipeline keeps feeding the CVE stream. Bugs that need a reversible PRNG, a leak, and an SMT solver used to be the kind of thing only a specialist would bother weaponizing. Now the hard part comes pre-solved in the writeup, and the attacker's job is copy, paste, and point at Shodan.

Key Takeaways

  • CVE-2026-61500 (CVSS 4.0 9.3) lets an unauthenticated attacker forge an HFS admin cookie and run code; fixed in HFS 3.2.1 on July 13.
  • Mythos chained a weak Math.random() signing key with an endpoint that leaked raw outputs, then used Z3 to recover the generator state.
  • Horizon3 published the chain September 30; VulnCheck saw exploitation from a China-based actor the next evening, plus four more hits Friday.
  • It is one of only two exploited CVEs among 300 Anthropic-credited ones in VulnCheck's tracker.
  • If you run HFS 3.0.0 to 3.2.0, upgrade and check for unfamiliar custom server code; if you write Node, keep Math.random() away from secrets.

Sources: Horizon3.ai disclosure, The Register, VulnCheck advisory, HFS v3.2.1 release, Anthropic CVE tracker, CVE record, V8 blog on Math.random

AISecurityClaude MythosProject GlasswingVulnerabilitiesOpen SourceRejetto HFS
CONSOLE
$