CVE-2026-37012
nicheHardcoded API credentials in PentestGPT expose user telemetry data
A hardcoded-credential flaw (CWE-798) in pentestgpt/core/langfuse.py of PentestGPT 1.0.0 embeds fixed Langfuse API credentials in the source, so anyone who extracts them can authenticate to the project's Langfuse telemetry backend over the network without privileges or user interaction. An attacker who recovers these credentials can read sensitive user telemetry data collected from PentestGPT sessions, producing a confidentiality-only impact (CVSS 3.1 score 7.5). Users running PentestGPT 1.0.0 with telemetry enabled are affected. No exploitation has been observed: there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns only a 0.4% probability of exploitation within 30 days.
What to do: Audit any PentestGPT 1.0.0 installation by inspecting pentestgpt/core/langfuse.py for the embedded Langfuse API credentials, disable telemetry or remove/rotate those credentials, and check the project for a patched release (no fixed version is identified in the advisory data). Users who enabled telemetry should assume recorded session telemetry may be readable by third parties holding the hardcoded keys.
| PentestGPT (open-source project) PentestGPT | 1.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in pentestgpt/core/langfuse.py in PentestGPT 1.0.0 allows remote attackers to disclose sensitive user telemetry data via hardcoded API credentials.
- Weakness
- CWE-798
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.