{"id":"GHSA-w72w-9qmj-c9qm","summary":"AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secrets","details":"### Summary\nThe telemetry subsystem embeds a hardcoded auth token (`\"secret\"`) in the public source and transmits raw CLI arguments—including `--secret`, `--jwt_secret`, and `--http_rpc_secret` values—to a third-party telemetry endpoint.\n\n### Details\nIn `telemetry/config.go` line 12, `var authToken = \"secret\"` is committed in the public repository and used to authenticate to `https://telemetry.anycable.io`. In `telemetry/telemetry.go`, `clusterFingerprint()` (line 320) calls both `anycableFileConfig(c.ConfigFilePath)` (line 333), which reads the full TOML config file contents, and `anycableCLIArgs()` (line 402), which reads `os.Args[1:]` verbatim—including any `--secret=...`, `--jwt_secret=...`, `--http_rpc_secret=...` arguments. Both raw values are passed to `generateDigest()` (line 373), meaning the actual secret strings flow through the code path and are included in telemetry data sent to the third-party server. Since the hardcoded `authToken = \"secret\"` is public, any attacker who can perform DNS hijacking or is positioned on the network path can intercept and read the telemetry payload containing operator credentials.\n\n### PoC\n1. Read `telemetry/config.go` in the public repo to find `authToken = \"secret\"`.\n2. Set up a DNS spoof for `telemetry.anycable.io` pointing to an attacker-controlled server.\n3. Start anycable-go with `--secret=my-production-secret`.\n4. The server sends a POST to the attacker's endpoint with the telemetry JSON payload. The `clusterFingerprint` field contains data derived from raw `os.Args` including `--secret=my-production-secret`.\n\n### Impact\nIn MITM/DNS-hijack scenarios, production secrets (JWT secrets, broadcast keys, RPC auth) are exposed to third parties. The hardcoded `authToken = \"secret\"` provides no protection since it is known to anyone reading the open-source code.\n\n### Fix\n1. Remove the hardcoded `authToken` from source; generate or require operator configuration at build time or deployment time. 2. Remove `anycableCLIArgs()` from the fingerprint computation, or sanitize it to exclude values of secret-bearing flags before hashing. 3. Add a documented opt-out mechanism for telemetry.","aliases":["CVE-2026-63406","GO-2026-6529"],"modified":"2026-09-28T17:11:11.851359767Z","published":"2026-09-18T17:17:29Z","database_specific":{"github_reviewed_at":"2026-09-18T17:17:29Z","nvd_published_at":null,"cwe_ids":["CWE-312","CWE-798"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/anycable/anycable/security/advisories/GHSA-w72w-9qmj-c9qm"},{"type":"WEB","url":"https://github.com/anycable/anycable/commit/201c67e99e463ed63bd6b345562f4c458385fcee"},{"type":"PACKAGE","url":"https://github.com/anycable/anycable"},{"type":"WEB","url":"https://github.com/anycable/anycable/releases/tag/v1.6.15"}],"affected":[{"package":{"name":"github.com/anycable/anycable","ecosystem":"Go","purl":"pkg:golang/github.com/anycable/anycable"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.6.15"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-w72w-9qmj-c9qm/GHSA-w72w-9qmj-c9qm.json","last_known_affected_version_range":"\u003c= 1.6.14"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}