Anthropic Mythos AI Finds Rejetto HFS Flaw That Lets Attackers Forge Admin Sessions and Execute Code
Anthropic's Mythos AI found critical Rejetto HFS flaw CVE-2026-61500, letting attackers forge admin sessions and achieve remote code execution via predictable session keys.
CVE-2026-61500 in Rejetto HFS 3.x stems from session-signing keys generated with JavaScript's non-cryptographic Math.random() (xorshift128+ PRNG). Horizon3, working in Anthropic's Project Glasswing with the Mythos Preview model, found the flaw and built a Z3-based proof of concept that recovers the server startup signing key and forges administrator session cookies. The forged cookie can bypass session IP restrictions, and HFS administrative APIs allow arbitrary JavaScript execution, turning the auth bypass into full remote code execution. The finding highlights concern that AI-assisted vulnerability research may make complex exploit chains more accessible to threat actors.