Vulnerability GHSA-32gc-wf3m-78w9

High Risk
HIGH RISK
CVSS Score: 8.8
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 hours ago
October 09, 2026 at 05:07 PM UTC
0xJacky/nginx-ui /api/nodes Leaks Cluster Node Tokens and Allows Cross-Node Impersonation as initUser
>=1.9.10-0.20250517140552-daee3ac7ade1 <1.9.10-0.20260728091109-0ecbd106c37b
>=1.9.10-0.20250517140552-daee3ac7ade1 <1.9.10-0.20260728091109-0ecbd106c37b

Summary

0xJacky/nginx-ui /api/nodes Leaks Cluster Node Tokens and Allows Cross-Node Impersonation as initUser

Details

Summary 0xJacky/nginx-ui contains a high-severity trust-boundary failure between ordinary users and cluster node credentials. The source code shows that cluster node list and detail endpoints are reachable by ordinary authenticated users and return node objects containing the token field.

That same token is also used as the X-Node-Secret shared credential for node-to-node authentication. When the middleware receives a correct node secret, it upgrades the request to initUser and bypasses the normal user-authentication path. As a result, any low-privileged authenticated user can first read a node token from /api/nodes and then impersonate a trusted node against a remote node's management API, achieving cross-node administrative authentication bypass.

Details The root cause is a combination of sensitive credential exposure and improper trust elevation for node-to-node authentication. First, router/routers.go:87-105 mounts cluster.InitRouter(g) inside the shared /api authenticated route group, so any successfully authenticated user can access node list and detail endpoints.

Next, api/cluster/node.go:19-48 implements GetNode and GetNodeList by directly returning analytic.GetNode(node). Meanwhile, model/node.go:8-13 defines Token with the JSON tag json:"token", meaning the node secret is serialized into API responses. The surrounding code path does not redact that field. Therefore, a low-privileged user can call /api/nodes or /api/nodes/:id and retrieve both the target node URL and the token value used for trusted node authentication.

The second half of the exploit chain is in internal/middleware/middleware.go:73-103. The middleware reads a node secret from the X-Node-Secret header or node_secret query parameter. If that supplied value matches settings.NodeSettings.Secret, the request is immediately associated with user.GetInitUser(c), stored in the context as user, and allowed to continue. In other words, possession of the node secret is treated as sufficient to become initUser and bypass the normal JWT-based user-authentication flow.

This makes the disclosed token directly reusable for privilege escalation. A low-privileged user logs in to the primary instance, retrieves the cluster node token through /api/nodes, then sends a request to the remote node with X-Node-Secret set to the leaked token. Because the remote node upgrades the request to initUser, the attacker can invoke sensitive management handlers. The verified evidence identifies api/system/router.go and api/system/restart.go as examples of reachable high-risk operations, including POST /api/system/restart.

Core vulnerable code path:

go // router/routers.go:87-105 g := root.Group("/", middleware.AuthRequired(), middleware.Proxy()) { debug.InitRouter(g) user.InitUserRouter(g) analytic.InitRouter(g) user.InitManageUserRouter(g) nginx.InitRouter(g) sites.InitRouter(g) streams.InitRouter(g) config.InitRouter(g) template.InitRouter(g) certificate.InitCertificateRouter(g) certificate.InitDNSCredentialRouter(g) certificate.InitAcmeUserRouter(g) dnsapi.InitRouter(g) system.InitPrivateRouter(g) settings.InitRouter(g) llm.InitRouter(g) cluster.InitRouter(g) notification.InitRouter(g) external_notify.InitRouter(g) backup.InitAutoBackupRouter(g) nginxLog.InitRouter(g) upstream.InitHTTPRouter(g) g.GET("/geolite/status", geolite.GetStatus) } This route block shows that cluster endpoints are mounted in the shared authenticated route group. Any user with a valid JWT can reach cluster management APIs; there is no administrator-only authorization gate here.

go // api/cluster/node.go:19-48 func GetNode(c *gin.Context) { id := cast.ToUint64(c.Param("id"))

nodeQuery := query.Node

node, err := nodeQuery.FirstByID(id)
if err != nil {
	cosy.ErrHandler(c, err)
	return
}

c.JSON(http.StatusOK, analytic.GetNode(node))

}

func GetNodeList(c *gin.Context) { core := cosy.Core model.Node. SetFussy("name")

// fix for sqlite
if c.Query("enabled") != "" {
	core.GormScope(func(tx *gorm.DB) *gorm.DB {
		return tx.Where("enabled = ?", cast.ToInt(cast.ToBool(c.Query("enabled"))))
	})
}

core.SetTransformer(func(m *model.Node) any {
	return analytic.GetNode(m)
})

core.List()

} These handlers return node information directly to authenticated users. Because the returned object ultimately embeds the raw model.Node and that model contains a JSON token field, the API leaks the remote node shared secret.

go // model/node.go:8-13 type Node struct { Model Name string json:"name" URL string json:"url" Token string json:"token" Enabled bool json:"enabled" gorm:"default:false" } The model definition confirms that Token is JSON-serializable. This is a core part of the sensitive-information exposure because the field is not restricted to internal-only use.

go // internal/middleware/middleware.go:73-103 // getNodeSecret from header or query func getNodeSecret(c *gin.Context) (secret string) { if secret = c.GetHeader("X-Node-Secret"); secret != "" { return secret }

return c.Query("node_secret")

}

// AuthRequired is a middleware that checks if the user is authenticated func AuthRequired() gin.HandlerFunc { return func(c *gin.Context) { abortWithAuthFailure := func() { c.AbortWithStatusJSON(http.StatusForbidden, gin.H{ "message": "Authorization failed", }) }

	xNodeID := getXNodeID(c)
	if xNodeID != "" {
		c.Set("ProxyNodeID", xNodeID)
	}

	// Check node secret authentication
	if nodeSecret := getNodeSecret(c); nodeSecret != "" && nodeSecret == settings.NodeSettings.Secret {
		initUser := user.GetInitUser(c)
		c.Set("Secret", nodeSecret)
		c.Set("user", initUser)
		c.Next()
		return
	}

This authentication logic converts knowledge of the leaked node secret into an authenticated request as initUser. That makes the disclosed token immediately reusable for cross-node privilege escalation.

POC Prerequisites: (1) the attacker has a valid low-privileged user account, (2) at least one cluster node is configured, and (3) the target node management address is reachable from the current deployment, which is typical in clustered setups.

Reproduction steps:

Log in as a low-privileged user with POST /api/login using a request body containing name and password. Capture the returned JWT token. Request GET /api/nodes or GET /api/nodes/:id with the low-privileged user's Authorization token. Inspect the JSON response and extract the target node's url and token fields. The token is the shared secret accepted by the remote node as X-Node-Secret. Send a sensitive management request directly to the target node, such as POST /api/system/restart, with the leaked token in the X-Node-Secret header. If the target node returns 200 or an equivalent success response, the request has been accepted as trusted node traffic. Expected result: the attacker performs administrative actions on the remote node without possessing a legitimate high-privileged user session on that node, demonstrating cross-node authentication bypass and privilege escalation to initUser-level access.

Impact Any ordinary authenticated user can extract cluster node shared secrets and convert them into direct authentication bypass on remote nodes. The attacker can then execute high-risk administrative actions such as system restart, Nginx reload/restart, and configuration synchronization, enabling lateral movement across managed nodes and ultimately full compromise of the cluster management plane. The issue combines sensitive information disclosure with privilege escalation.

Remediation Do not return cluster node tokens in normal API responses. Use dedicated output DTOs for node APIs and fully redact or omit the token field. Require administrator-level authorization for node-management endpoints instead of exposing them to every authenticated user. X-Node-Secret should not be shared with the normal HTTP management plane; it should be restricted to controlled network paths or stronger node-to-node trust channels such as mutually authenticated connections. Even when node-secret authentication succeeds, its capabilities should be minimized rather than mapping directly to a general-purpose initUser identity.

Disclosure Notes The affected version is identified from the report-generation context as v2.4.2. No fixing commit, patched release, or vendor advisory was verified during this reporting stage, so patched_versions is marked as to be confirmed. The narrative below is based only on verified source-code evidence and the managed-vulnerability metadata.

Supplemental Information Affected products Ecosystem: self-hosted Package name: 0xJacky/nginx-ui Affected versions: v2.4.2 Patched versions: to be confirmed

Related Vulnerabilities

Other vulnerabilities affecting the same packages

High Risk
3 hours ago
Nginx UI: Self-upgrade runs an unsigned binary verified only by a same-origin digest → RCE via a compromised mirror or MITM
>=1.9.10-0.20250517140552-daee3ac7ade1 <1.9.10-0.20260728114330-580585516dd8 GHSA-662p-52hx-cmh2
>=1.9.10-0.20250517140552-daee3ac7ade1 <1.9.10-0.20260728114330-580585516dd8 GHSA-662p-52hx-cmh2
High Risk
3 hours ago
Nginx UI: Authentication bypass: password login does not enforce a passkey-only second factor (2FA bypass)
>=1.9.10-0.20250517140552-daee3ac7ade1 <1.9.10-0.20260728074558-95cd21b70814 GHSA-45gv-9wjv-xh7p
>=1.9.10-0.20250517140552-daee3ac7ade1 <1.9.10-0.20260728074558-95cd21b70814 GHSA-45gv-9wjv-xh7p
High Risk
3 hours ago
Nginx-UI AuthRequired token cookie fallback enables CSRF against management APIs
>=1.9.10-0.20250517140552-daee3ac7ade1 <1.9.10-0.20260728074433-a3999bd78a3b GHSA-33rr-wq23-g6gg
>=1.9.10-0.20250517140552-daee3ac7ade1 <1.9.10-0.20260728074433-a3999bd78a3b GHSA-33rr-wq23-g6gg
High Risk
3 hours ago
Nginx UI: Incomplete fix of CVE-2026-84315 - the api/cluster router was not - wrapped in RequireSecureSession, so those sensitive mutations run without OTP step-up
>=1.9.10-0.20250517140552-daee3ac7ade1 <1.9.10-0.20260728074433-a3999bd78a3b GHSA-h246-wpgf-vmq5
>=1.9.10-0.20250517140552-daee3ac7ade1 <1.9.10-0.20260728074433-a3999bd78a3b GHSA-h246-wpgf-vmq5
High Risk
3 hours ago
Nginx UI: Node Secret Credential Exposure via URL Query Parameter
>=1.9.10-0.20250517140552-daee3ac7ade1 <1.9.10-0.20260728074433-a3999bd78a3b GHSA-pvgv-gcp7-v38g
>=1.9.10-0.20250517140552-daee3ac7ade1 <1.9.10-0.20260728074433-a3999bd78a3b GHSA-pvgv-gcp7-v38g
View all vulnerabilities for these packages

Timeline

Published
3 hours ago
October 09, 2026 at 05:07 PM UTC
Last Modified
3 hours ago
October 09, 2026 at 05:15 PM UTC