VYPR

outstatic

by Avitorio

CVEs (1)

  • CVE-2026-52539Jul 30, 2026
    risk 0.00cvss epss 0.00

    Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default value which is publicly visible in the source code repository. An unauthenticated remote attacker can exploit this…