CVE-2026-28678

HIGH

DSA Study Hub - Info Disclosure

Title source: llm
STIX 2.1

Description

DSA Study Hub is an interactive educational web application. Prior to commit d527fba, the user authentication system in server/routes/auth.js was found to be vulnerable to Insufficiently Protected Credentials. Authentication tokens (JWTs) were stored in HTTP cookies without cryptographic protection of the payload. This issue has been patched via commit d527fba.

Scores

CVSS v3 8.1
EPSS 0.0003
EPSS Percentile 8.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-522 CWE-311
Status published
Products (1)
toxicbishop/dsa_study_hub < 2026-02-21
Published Mar 07, 2026
Tracked Since Mar 07, 2026