Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2026-50561: CWE-287: Improper Authentication in xerrors Yuxi

0
Critical
VulnerabilityCVE-2026-50561cvecve-2026-50561cwe-287
Published: 08/12/2026 (08/12/2026, 14:07:07 UTC)
Source: CVE Database V5
Vendor/Project: xerrors
Product: Yuxi

Description

Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior to version 0.6.2, the project's authentication mechanism contains a flaw. In affected versions, the system does not sufficiently validate the identity token in the Authorization header — only performing a validity check. This allows an administrator token generated in another deployment instance or local testing environment to be used to access the backend management interfaces of a different affected instance. An attacker who obtains or constructs an acceptable administrator Authorization token may bypass normal login authentication and gain administrator privileges. This vulnerability could allow an attacker to access system configurations, invoke backend management APIs, create administrator accounts, and ultimately take over the system backend. This issue has been fixed in version 0.6.2. Before upgrading, users are advised to implement the following temporary measures: Set the environment variable `JWT_SECRET_KEY` to a non-default value, and configure a unique, sufficiently strong JWT/authentication key for each deployment instance; and/or avoid exposing backend management interfaces directly to the public network.

CVSS v3.1

Score 9.4critical

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
Low
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

Affected software

GitHub Actionsmore threats →ai
xerrors/Yuxi
pkg:github/xerrors/Yuxi
Affected versions
<0.6.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 14:41:20 UTC

Technical Analysis

Yuxi, a large-model-based knowledge base and graph agent platform, suffers from an improper authentication vulnerability (CWE-287) in versions before 0.6.2. The platform only performs a validity check on the identity token in the Authorization header without verifying its origin or uniqueness per deployment. Consequently, administrator tokens generated in other instances or local environments can be reused to access backend management interfaces on different affected instances. An attacker with such a token can bypass normal authentication, invoke backend APIs, create administrator accounts, and take over the system. This vulnerability has been addressed in version 0.6.2. Temporary mitigations include setting a unique, strong JWT_SECRET_KEY per deployment and restricting public exposure of backend interfaces.

Potential Impact

An attacker who obtains or crafts an administrator Authorization token valid in another deployment can bypass authentication controls and gain administrator privileges on an affected Yuxi instance. This allows unauthorized access to system configurations, backend management APIs, and the ability to create administrator accounts, leading to full system backend compromise. The CVSS score of 9.4 reflects the critical impact with network attack vector, no privileges required, no user interaction, and high confidentiality, integrity, and low availability impacts.

Mitigation Recommendations

A fix is available in Yuxi version 0.6.2. Users should upgrade to this version to fully remediate the vulnerability. Until upgrading, users are advised to set the environment variable JWT_SECRET_KEY to a unique, strong value per deployment instance to prevent token reuse across deployments. Additionally, avoid exposing backend management interfaces directly to the public network to reduce attack surface.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-06-04T21:34:34.426Z
Cvss Version
3.1
State
PUBLISHED
Remediation Level
null

Threat ID: 6a7c82b6bf8831d539ab967b

Added to database: 08/12/2026, 14:27:02 UTC

Last enriched: 08/12/2026, 14:41:20 UTC

Last updated: 08/12/2026, 23:39:28 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses