Anthropic Mythos Found A Bug in Rejetto HFS. Attackers Are Now Exploiting It.

Wait 5 sec.

AI-assisted research uncovered a critical Rejetto HFS flaw that enables authentication bypass and remote code execution, now exploited in the wild.A Rejetto HFS vulnerability, tracked as CVE-2026-61500 (CVSS score of 9.3), discovered with the help of the Anthropic Mythos AI model is now being exploited in the wild, turning an interesting security research experiment into a much more practical warning for defenders.The vulnerability affects Rejetto HTTP File Server (HFS) 3.x. Attackers can exploit it to bypass authentication, obtain administrative access and ultimately execute arbitrary code on the server. VulnCheck observed reconnaissance activity targeting vulnerable systems.“Earlier today, VulnCheck‘s Canary Intelligence network started detecting probes for CVE-2026-61500, a session-forgery-via-weak-signing-key vulnerability in Rejetto HFS, an open-source file server.” VulnCheck warned. “The vulnerability was discovered by Horizon3.ai‘s Zach Hanley and published through the VulnCheck CNA on July 13, 2026.”The story is interesting for two reasons. The first is the vulnerability itself. The second is how Horizon3 found it.Rejetto HFS is an open-source application designed to make file hosting and sharing easy. Its earlier 2.x releases were written in Delphi, while the newer 3.x branch was rewritten in TypeScript. HFS had already appeared in CISA’s Known Exploited Vulnerabilities catalog because of CVE-2024-23692, an unauthenticated template injection that could lead to remote code execution.Horizon3 analyzed the new code using a custom research setup and Anthropic’s Mythos model as part of Project Glasswing. Since joining the project in July 2026, the company says it has used Mythos to find serious vulnerabilities, focusing on flaws that attackers could realistically discover and exploit at scale.That distinction matters. Finding a bug is one thing. Finding a bug that can be turned into a reliable attack is much harder.Horizon3 researchers say Mythos performed particularly well in scientific tasks, computer science, operating system internals, math, and problems that require many steps. The HFS vulnerability is a good example. The model did not just spot a weak cryptographic design. It connected several different issues and worked out how they could be combined to achieve remote code execution.The problem starts with authentication. HFS generates a value using JavaScript’s Math.random(). That value goes into Koa, the Node.js web framework used by HFS, and Koa uses it through Keygrip to sign session cookies. If an attacker can recover the value used as the signing key, the attacker can create valid session cookies.“To fully explain the issue, first, we’ll detail how authentication works in HFS, and then how Mythos identified the issue.” states the report published by Horizon.HFS generates a “random” value with Math.random()The “random” value is passed to Koa, which is the Node.js web framework HFS is built onKoa uses keygrip to sign all session cookies with that “random” valueIf an attacker can derive what the session signing key is, they can forge valid session cookies. Typically, this should not be possible if using a secure pseudo random number generator (PRNG).”Normally, this would be difficult. But HFS used V8’s Math.random(), which is based on the xorshift128+ pseudo-random number generator. It is not designed for security, and its output can be predicted if an attacker collects enough values.The bigger problem was that HFS exposed values from the same random-number stream. During login, HFS put a Math.random() value into the session state, and the session cookie sent that value to the client. This meant an attacker could collect random values from the same generator that was used to create the signing key.Mythos recognized the connection. It identified both the insecure random-number generator used to create the signing key and the separate code path that leaked values from that same generator. From there, it determined that the leaked values could provide enough information to reconstruct the generator’s internal state and work backwards to the values generated when the server started.That requires mathematics, not just source-code pattern matching.The xorshift128+ generator maintains an internal state made from two 64-bit values. Its operations are reversible, meaning that enough consecutive outputs can be used to reconstruct the state and then move backwards through previous outputs.“In V8, Node.js’s JavaScript engine, when calling Math.random() the PRNG is generated with xorshift128+ algorithm. “We won’t dive into the algorithm itself, but critically the outputs of it are reversible. If you can observe other numbers generated by Math.random(), it is possible given enough observations to know the previous numbers that were generated.” continues the report. “This would allow an attacker to forge valid authentication cookies.”Mythos proposed using Z3, Microsoft’s open-source satisfiability modulo theories solver, to solve the mathematical constraints. Horizon3’s researchers point out that they would normally have considered brute force first, and that they hadn’t previously seen an SMT solver used in this way to turn a cryptographic weakness in a real application into an authentication bypass.The model also didn’t stop at the theoretical observation. It produced a working proof of concept, implemented the Z3 solver with the required constraints and demonstrated arbitrary command execution.That distinction is important. Security teams have been discussing AI-assisted vulnerability discovery for a while, but there is a major difference between an AI system saying “this looks suspicious” and an agent figuring out how several weak points can be chained into a working attack.The complete attack chain starts with user enumeration to establish whether the built-in administrator account exists. Horizon3 says Mythos also identified the user-enumeration weakness needed to complete the chain.The attacker then collects leaked Math.random() outputs from an unauthenticated endpoint. Horizon3’s exploit samples the endpoint 12 times, feeds the observations into Z3, reconstructs the internal xorshift128+ state and walks that state backwards to recover the signing key created when the HFS process started.With that key, the attacker can forge an administrator session cookie. HFS then accepts the forged session as authenticated, allowing the attacker to reach functionality that can execute code on the server.The chain therefore moves from unauthenticated access to random-number leakage, from leakage to state recovery, from state recovery to cookie forgery, and from cookie forgery to administrative control and remote code execution.There was no need for a spectacular memory corruption bug. No exotic kernel exploit was required. The attacker gets there by combining a weak source of randomness, information leakage and an application that trusts the resulting session state.Horizon3’s researchers say this type of cryptographic weakness has often been abandoned during manual research because proving real impact can take too much time and requires mathematical expertise. Mythos changes that calculation because it can investigate the weakness, identify the missing link and solve the mathematical problem without requiring a researcher to manually direct every step.“It did not require follow-on prompting to find the disparate PRNG leak that made this theoretical issue a demonstrable one.” Horizon continues. “It did not require instruction to go out and research approaches to “solve” a complex mathematical problem.”Horizon3 argues that as AI systems become better at reasoning across code, mathematics and long sequences of operations, attackers may start weaponizing vulnerabilities that were previously considered too difficult or unreliable to exploit at scale. A vulnerability class doesn’t necessarily become more dangerous because the underlying bug changed. It can become more dangerous because the cost of turning that bug into an exploit has fallen.A human researcher might spot that an application uses Math.random() for something security-sensitive and move on after deciding that exploiting it would take too much effort. An AI agent can keep going, inspect another code path, find the leaked values, connect the two observations, formulate the mathematical constraints and test whether the resulting attack actually works.Horizon3 also makes an important qualification. Its researchers don’t argue that security researchers have become irrelevant. Their role changes because someone still has to decide which projects deserve deeper investigation, which libraries are important enough to justify specialized analysis, and where an automated scan is likely to find something useful.The company also notes that models available in 2025 could already identify vulnerabilities, but researchers needed substantial software engineering around them to manage context, select relevant files and functions, and guide the analysis. Newer models and supporting libraries have reduced some of those limitations, making relatively simple instructions such as “find vulnerabilities” or “find a bypass” much more effective against projects that haven’t received extensive security review.HFS was patched in version 3.2.1, released on July 13. Rejetto warned that multiple security vulnerabilities had affected previous versions and could allow attackers to obtain administrative access.The fact that exploitation has now appeared makes the disclosure more than an interesting demonstration of AI capability. VulnCheck reported on October 2 that attackers had started targeting CVE-2026-61500 in small-scale reconnaissance activity originating from a China Telecom IP address, with observed attempts hitting canaries in Japan and the United States.“Activity so far looks to be small-scale reconnaissance only, with a single China Telecom IP probing Canary deployments in Japan and the United States.” VulnCheck added. “CVE-2026-61500 affects Rejetto HFS file server versions 3.0.0–3.2.0 and allows for account takeover and remote code execution.”For defenders, the practical lesson is uncomfortable but simple: a vulnerability that once looked too complicated to weaponize may no longer have that protection.And AI doesn’t need to invent a new attack technique to change the equation. It can take a collection of ordinary weaknesses, do the tedious reasoning between them and produce the exploit that a human researcher might have decided wasn’t worth the time.“The security research space has changed, is still changing, and expect that we’ll continue to have to adapt as it shifts.” concludes the report.Follow me on Twitter: @securityaffairs and Facebook and MastodonPierluigi Paganini(SecurityAffairs – hacking, Rejetto HFS)