A critical authentication bypass in Yuxi allowed administrator JWTs created in one deployment, including local test environments, to be reused against other internet-exposed Yuxi instances. The flaw, tracked as CVE-2026-50561 and GHSA-6959-99pq-c56x, stemmed from improper Authorization header validation and insufficient binding of tokens to a specific instance and identity context. A successful attack could let an unauthenticated remote actor bypass login, access system configuration, invoke backend management APIs, create new administrator accounts, and fully take over the backend.
Project maintainers acknowledged the issue in a public GitHub report before moving details into a private security process, and fixed it in Yuxi 0.6.2. The patch removed reliance on a historical default JWT secret, required or generated per-instance JWT secrets and instance identifiers, enforced issuer and audience checks during token creation and verification, and blocked deleted or login-locked users from continuing to use previously issued tokens. The update also added environment and initialization changes to persist JWT settings, along with new tests for the strengthened authentication controls; temporary mitigation guidance advised setting a unique non-default JWT_SECRET_KEY and avoiding direct public exposure of backend management interfaces.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-50561 was published for the critical Yuxi improper authentication flaw affecting versions before 0.6.2, describing cross-instance administrator token reuse and backend takeover risk. The entry linked the issue to GHSA-6959-99pq-c56x and the fixing commit, and noted the CVE was received from GitHub Security Advisories.
A Yuxi commit explicitly referencing GHSA-6959-99pq-c56x fixed the authentication bypass by removing acceptance of the legacy default JWT secret, requiring or generating per-instance JWT settings, and enforcing issuer and audience validation. The patch also blocked continued access by deleted or login-locked users using previously issued tokens and added tests for the new controls.
A public GitHub issue reported that Yuxi improperly validated Authorization header tokens, allowing an administrator JWT from a local or different deployment instance to be reused against other internet-exposed Yuxi instances. The report included proof-of-concept access to backend configuration and admin-user creation endpoints.
The project owner confirmed the security issue, said it would be handled through a private GitHub Security Advisory, and closed the public issue because it contained sensitive exploit details. The maintainer also said the flaw was planned to be fixed in Yuxi version 0.6.2 and that a CVE would be requested after release.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.