Mythos AI Discovers Critical Session Forgery Flaw in Rejetto HFS

Mythos AI, built by Anthropic under the Project Glasswing initiative, has uncovered a severe vulnerability in Rejetto HTTP File Server (HFS) that allows attackers to forge administrator sessions and run arbitrary code. The flaw has been cataloged as CVE-2026-61500 and arises from the use of a weak, predictable method for signing session cookies.

The Weak Link: Predictable Session Keys

The root cause lies in how the TypeScript-based HFS 3.x branch generates session-signing keys. If the configuration item COOKIE_SIGN_KEYS isn’t explicitly defined, HFS falls back to calling randomId(30), which in turn uses JavaScript’s Math.random(). That function is not cryptographically secure and relies on the xorshift128+ algorithm under Node.js’s V8 engine. An attacker who captures enough consecutive values from that pseudo-random stream can reverse-engineer its internal state.

From Forged Cookie to Remote Code Execution

During the login process—specifically at the loginSrp1 endpoint—HFS generates a session identifier using Math.random() and stores it in a client-side cookie. That cookie is signed but not encrypted. An attacker can decode the cookie, observe high-precision random values, and use tools like Z3 to recover the PRNG’s internal state. From there, it’s possible to derive the session-signing key used at server startup.

With that signing key in hand, the attacker can craft a cookie impersonating the administrator, even bypassing restrictions like IP-based session guards. Once inside as an admin, the attacker can exploit HFS’s API endpoints to execute arbitrary JavaScript code, turning a session forgery into full remote code execution.

Implications and Advice for HFS Users

Mythos AI, through its analysis, not only flagged the insecure PRNG usage, but mapped out an exploit path, built a proof-of-concept with Z3, and demonstrated command execution on a vulnerable server. This raises alarms that AI tools are lowering the bar for finding and weaponizing complex vulnerabilities—bugs that once required deep cryptographic knowledge may now be more accessible.

Administrators of Rejetto HFS should take immediate action: update to the fixed version once it’s published, set strong COOKIE_SIGN_KEYS, stop using Math.random() for any security-critical values, restrict public access to admin functions, and monitor logs for unexpected authentication behavior or the creation of custom endpoints.

What This Means: This discovery underlines the growing role of AI-assisted vulnerability research in both defense and offense. As tools like Mythos become more capable of chaining together weak components into a full exploit, software that relies on non-secure randomness is increasingly at risk. Developers need to assume that attackers have access to similar AI-powered capabilities—and make cryptographic security the default, not an option.