CVE-2026-32303
Description
Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, an integrity check vulnerability allows an attacker to tamper with the vault configuration file leading to a man-in-the-middle vulnerability in Hub key loading mechanism. Before this fix, the client trusted endpoints from the vault config without host authenticity checks, which could allow token exfiltration by mixing a legitimate auth endpoint with a malicious API endpoint. Impacted are users unlocking Hub-backed vaults with affected client versions in environments where an attacker can alter the vault.cryptomator file. This issue has been patched in version 1.19.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:cryptomator:cryptomator:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:cryptomator:cryptomator:*:*:*:*:*:*:*:*range: <1.19.1
- (no CPE)range: <1.19.1
- (no CPE)range: < 1.19.1
Patches
Vulnerability mechanics
References
4- github.com/cryptomator/cryptomator/commit/6b82abcd80449a30b561d823193f9ecea542a625nvdPatch
- github.com/cryptomator/cryptomator/security/advisories/GHSA-34rf-rwr3-7g43nvdVendor Advisory
- github.com/cryptomator/cryptomator/pull/4179nvdIssue Tracking
- github.com/cryptomator/cryptomator/releases/tag/1.19.1nvdRelease Notes
News mentions
0No linked articles in our index yet.