10.0 CRITICAL
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Changed (C)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Changed (C)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse dismissed (not in Nixpkgs)
SOCFortress CoPilot: Hardcoded JWT secret allows unauthenticated full admin compromise and lateral movement into all integrated SOC tools
SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a hardcoded JWT signing secret as a fallback value in backend/app/auth/utils.py:28 and ships it verbatim in .env.example. Any deployment where JWT_SECRET is not explicitly set — including the default Docker Compose setup — signs all authentication tokens with this publicly known value. An unauthenticated attacker can forge arbitrary admin-scoped JWTs and gain full control of the application and every security tool it manages without any credentials. This vulnerability is fixed in 0.1.57.
References
-
https://github.com/socfortress/CoPilot/security/advisories/GHSA-4gxj-hw3c-3x2x x_refsource_CONFIRM
-
https://github.com/socfortress/CoPilot/pull/814 x_refsource_MISC
Affected products
- ==< 0.1.57
Matching in nixpkgs
pkgs.gh-copilot
Ask for assistance right in your terminal
pkgs.copilot-cli
Build, Release and Operate Containerized Applications on AWS
pkgs.github-copilot-cli
GitHub Copilot CLI brings the power of Copilot coding agent directly to your terminal
pkgs.copilot-node-server
Copilot Node.js server
pkgs.copilot-language-server
Use GitHub Copilot with any editor or IDE via the Language Server Protocol
pkgs.haskellPackages.copilot
A stream DSL for writing embedded C programs
pkgs.copilot-language-server-fhs
Use GitHub Copilot with any editor or IDE via the Language Server Protocol
pkgs.haskellPackages.copilot-c99
A compiler for Copilot targeting C99
pkgs.haskellPackages.copilot-core
An intermediate representation for Copilot
pkgs.github-copilot-intellij-agent
GitHub copilot IntelliJ plugin's native component
-
nixos-unstable 1.4.5.4049
- nixpkgs-unstable 1.4.5.4049
- nixos-unstable-small 1.4.5.4049
-
nixos-25.11 1.4.5.4049
- nixos-25.11-small 1.4.5.4049
- nixpkgs-25.11-darwin 1.4.5.4049
pkgs.haskellPackages.copilot-theorem
k-induction for Copilot
pkgs.haskellPackages.copilot-language
A Haskell-embedded DSL for monitoring hard real-time distributed systems
pkgs.vscode-extensions.github.copilot
GitHub Copilot uses OpenAI Codex to suggest code and entire functions in real-time right from your editor
pkgs.haskellPackages.copilot-libraries
Libraries for the Copilot language
pkgs.fishPlugins.github-copilot-cli-fish
GitHub Copilot CLI aliases for Fish Shell
pkgs.haskellPackages.copilot-interpreter
Interpreter for Copilot
pkgs.python312Packages.llm-github-copilot
LLM plugin providing access to GitHub Copilot
pkgs.python313Packages.llm-github-copilot
LLM plugin providing access to GitHub Copilot
pkgs.python314Packages.llm-github-copilot
LLM plugin providing access to GitHub Copilot
pkgs.haskellPackages.copilot-prettyprinter
A prettyprinter of Copilot Specifications
pkgs.haskellPackages.ogma-language-copilot
Ogma: Runtime Monitor translator: Copilot Language Endpoints
Package maintainers
-
@wattmto wattmto <dev@wattmto.dev>
-
@arunoruto Mirza Arnaut <mirza.arnaut45@gmail.com>
-
@DamienCassou Damien Cassou <damien@cassou.me>
-
@malob Malo Bourgon <mbourgon@gmail.com>
-
@dbreyfogle Danny Breyfogle <dnbyfg@proton.me>
-
@hacker1024 hacker1024 <hacker1024@users.sourceforge.net>
-
@afh Alexis Hildebrandt <surryhill+nix@gmail.com>
-
@Zimmi48 Théo Zimmermann <theo.zimmermann@telecom-paris.fr>
-
@PerchunPak Perchun Pak <nixpkgs@perchun.it>