High severity7.5NVD Advisory· Published May 8, 2026· Updated May 8, 2026
CVE-2024-46508
CVE-2024-46508
Description
yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting YETI_AUTH_SECRET_KEY to a value other than SECRET).
Affected products
2cpe:2.3:a:yeti-platform:yeti:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:yeti-platform:yeti:*:*:*:*:*:*:*:*range: >=2.0,<2.1.12
- (no CPE)range: <2.1.12
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/RhinoSecurityLabs/CVEs/tree/master/CVE-2024-46507nvdExploitThird Party Advisory
- rhinosecuritylabs.com/research/cve-2024-46507-yeti-server-side-template-injection-ssti/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.