Anthropic Mythos AI Finds Rejetto HFS Flaw That Lets Attackers Forge Admin Sessions and Execute Code
Anthropic's Mythos AI found critical Rejetto HFS flaw CVE-2026-61500, letting attackers forge admin sessions and achieve remote code execution via predictable session keys.
CVE-2026-61500 in Rejetto HFS 3.x stems from session-signing keys generated with JavaScript's non-cryptographic Math.random() (xorshift128+ PRNG). Horizon3, working in Anthropic's Project Glasswing with the Mythos Preview model, found the flaw and built a Z3-based proof of concept that recovers the server startup signing key and forges administrator session cookies. The forged cookie can bypass session IP restrictions, and HFS administrative APIs allow arbitrary JavaScript execution, turning the auth bypass into full remote code execution. The finding highlights concern that AI-assisted vulnerability research may make complex exploit chains more accessible to threat actors.
- CVE-2026-61500: Math.random() session-signing keys are predictable in Rejetto HFS 3.x
- Attackers recover xorshift128+ state from leaked cookie values using a Z3 solver
- Forged admin cookies bypass IP restrictions, enabling arbitrary code execution
- Horizon3 found it via Anthropic's Project Glasswing using the Mythos model
- HFS previously hit by CVE-2024-23692 template-injection RCE
Vulnerabilities mentionedAll →
- CVE-2024-236929.899%Unauthenticated Template Injection RCE in Rejetto HTTP File Server 2.3mpublished · rejetto HTTP File Server KEV ransomware PoC ×5
Full article545 words · extracted from cybersecuritynews.com · click to collapse
Anthropic’s Mythos AI has identified a critical vulnerability in Rejetto HTTP File Server that could allow remote attackers to forge administrator sessions and execute arbitrary code.
The issue, tracked as CVE-2026-61500, stems from predictable session-signing keys generated through JavaScript’s non-cryptographic Math.random() function.
Horizon3 made the finding after joining Anthropic’s Project Glasswing in July 2026, which uses the Mythos Preview model and industry partners to identify and fix critical and open-source software flaws. Anthropic says Mythos can autonomously find high-severity vulnerabilities and develop sophisticated exploit paths.
Rejetto HTTP File Server, commonly called HFS, is an open-source application for hosting and sharing files. The project has previously faced security issues, including CVE-2024-23692, an unauthenticated template-injection flaw that enabled remote code execution in older HFS releases.
The newly disclosed flaw affects the TypeScript-based HFS 3.x branch. HFS uses the Koa Node.js framework for session management. When the COOKIE_SIGN_KEYS configuration is not set, the application creates a signing key through randomId(30). That function relies on Math.random() rather than a cryptographically secure random-number generator.

This creates a serious risk because Node.js’s V8 engine implements Math.random() using the xorshift128+ pseudo-random-number generator. The algorithm is fast but not designed for cryptographic security. An attacker can reconstruct its internal state if they obtain enough consecutive output values.
Anthropic Mythos AI Finds Rejetto HFS Flaw
Mythos reportedly identified that HFS leaked such outputs during its authentication process. The loginSrp1 endpoint generates a session identifier with Math.random() and stores it in a client-side session cookie.
Because the cookie is signed but not encrypted, an attacker can decode their own issued cookie and collect high-precision random values from the same V8 pseudo-random stream.
An attacker could repeatedly trigger the login process, recover the xorshift128+ internal state with a solver such as Z3, and step the state backward to derive the session-signing key created during server startup.
The recovered key could then be used to generate a valid session cookie claiming to belong to the HFS administrator account. The forged cookie can include fields that bypass session IP restrictions, such as allow_session_ip_change.
Once authenticated as an administrator, the attacker can abuse HFS administrative API functionality that supports custom endpoints and arbitrary JavaScript execution. This turns the authentication bypass into remote code execution on the affected server.
Horizon3 said Mythos not only found the weak PRNG use but also connected it to the exposed random values, developed a mathematical recovery approach, generated a working Z3-based proof of concept, and demonstrated arbitrary command execution.
The finding highlights a broader concern for defenders: AI-assisted vulnerability research may make complex flaws easier to weaponize. Bugs that once required cryptographic expertise, reverse engineering, and lengthy exploit development could become more accessible to threat actors as advanced models automate code analysis and exploit chaining.
HFS administrators should update to the vendor-fixed release when available, explicitly configure strong COOKIE_SIGN_KEYS, avoid relying on Math.random() for any security-sensitive value, restrict public access to administrative functions, and monitor logs for unusual authentication activity or unexpected custom endpoint creation.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.