CVE-2023-50481
Description
An issue was discovered in blinksocks version 3.3.8, allows remote attackers to obtain sensitive information via weak encryption algorithms in the component /presets/ssr-auth-chain.js.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CVE-2023-50481 exposes sensitive information in blinksocks 3.3.8 via weak encryption algorithms and non-random initialization vectors.
Root
Cause CVE-2023-50481 affects blinksocks version 3.3.8, where the component /presets/ssr-auth-chain.js employs weak encryption algorithms such as RC4 and uses fixed (non-random) initialization vectors (IV) for CBC and CFB modes [1][3]. This violates secure coding practices (CWE-329, CWE-1204) and can be exploited by remote attackers [3].
Exploitation
An attacker with network access to the proxy traffic can passively intercept communications. Because the encryption is deterministic due to the fixed IV and weak cipher, the attacker can decrypt the traffic without needing authentication or special privileges [3]. The vulnerability is located in multiple lines of ssr-auth-chain.js and ssr-auth-aes128.js [3][4].
Impact
Successful exploitation leads to information disclosure, potentially revealing all data transmitted through the blinksocks proxy, including credentials, personal data, or other sensitive information [1][4].
Mitigation
As of the publication date, no official patch has been released for this vulnerability [2][4]. Users are advised to upgrade to a newer version if available, or to avoid using version 3.3.8 and consider alternative secure proxy solutions.
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
blinksocksnpm | <= 3.3.8 | — |
Affected products
3- blinksocks/blinksocksdescription
- Range: = 3.3.8
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.