GHSA-6xp5-7rcx-xfgx: Critical severity go/github.com/sipcapture/homer-app vulnerability
Summary On every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an admin account with the password sipcapture (stored as a legacy SHA-256 hex hash). There is no first-login forced-change mechanism. Any attacker who reaches the login endpoint immediately gains full administrative access.
Details config/config.go lines 858-861: go // DefaultInternalAuthPasswordHash is the SHA-256 hex digest of the default // bootstrap password (cleartext: sipcapture). const DefaultInternalAuthPasswordHash = "883ffc1f37fd0fe542b0fb9740035c4383e7d976c411161d24e62edace280f90"
coordinator/services/authbootstrap.go lines 20-71: EnsureBootstrapAdminUser() runs at startup. If no admin user exists, it inserts a row with username=admin, passwordhash=DefaultInternalAuthPasswordHash. No forcechange, no firstlogin flag, no expiry is set.
coordinator/services/authbootstraptest.go line 114 confirms the plaintext: go u, err := svc.Authenticate(ctx, "admin", "sipcapture")
passwordhash/password.go lines 36-45: Legacy SHA-256 hex hashes are accepted via legacySHA256HexEqual, so the default credential is functional on any deployment.
PoC bash Authenticate with default credentials — works on any fresh Homer deployment curl -s -X POST http://<homer-host>/api/v3/auth \ -H 'Content-Type: application/json' \ -d '{"username":"admin","password":"sipcapture"}' Response: {"token":"<admin-jwt>","data":{"userGroup":"admin"}}
Use the token to access all admin functionality curl -H "Authorization: Bearer <admin-jwt>" http://<homer-host>/api/v3/users
Impact Use of Hard-coded Credentials (CWE-798). Any attacker who can reach a freshly deployed Homer instance gains immediate full administrative access using the publicly documented default password, with no lockout, rate limiting, or forced password change required.
Fix Remove the hardcoded DefaultInternalAuthPasswordHash constant. Require operators to provide a hashed admin password in the configuration file. Alternatively, generate a random password on first startup, print it to stdout once, and immediately force a change on first login.
If possible, please apply for a CVE number when posting.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/sipcapture/homer-appto a version that resolves this vulnerability.Fixed in 0.0.0-20260625091610-b2e942031ff8 - Configuration
Require operators to provide a hashed admin password in the configuration file instead of using the hardcoded default password `sipcapture`.
Homer internal authentication bootstrap admin password = operator-provided hashed password
Event History
Frequently Asked Questions
Which deployments are exposed?
Fresh Homer deployments that use internal authentication are exposed if an attacker can reach the login endpoint. The bootstrap routine creates the account only when no administrator account exists.
What does an attacker need to exploit this?
No prior account, privileges, or user interaction are required. An attacker only needs network access to the login endpoint and can authenticate with the bootstrap administrator credentials.
How can I check whether this condition exists?
Check whether the deployment uses internal authentication and whether an admin user was created by bootstrap with the password hash 883ffc1f37fd0fe542b0fb9740035c4383e7d976c411161d24e62edace280f90. The affected bootstrap account uses the username admin.
Does the bootstrap account require a password change before it can be used?
No. The bootstrap process does not set a forced-change, first-login, or password-expiry control for the created administrator account.