External risk intelligence

Crawlab Hardcoded JWT Secret Allows Administrator Token Forgery

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-90945

Crawlab is a distributed web crawler management platform that typically exposes a web-based dashboard and API for managing crawling tasks and nodes. These services are commonly deployed in environments where administrators need to access the interface over a network, making the administrative API and web interface a likely internet-facing or edge-reachable component in many deployments.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects the Crawlab platform, specifically how it handles security tokens. The system uses a fixed, hard-coded secret to sign important tokens, which an attacker could exploit to impersonate administrators. This could allow them to gain unauthorized access to administrative functions and potentially run malicious code on connected systems.

  • Unprotected secret allows unauthorized admin access.
  • Hard-coded secret is a critical, long-term risk.
  • Confirm if this platform is in use.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit a hard-coded secret used for signing security tokens. This allows them to create their own tokens, granting them administrative access to the system. Once authenticated as an administrator, they can potentially execute code on connected worker nodes.

  • Network access and no authentication needed.
  • Forging administrator tokens.
  • Execute code on worker nodes.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker could forge administrator tokens to access administrative APIs and execute code on worker nodes. This is possible due to a hard-coded secret used for signing JWT tokens, which cannot be changed through configuration or environment variables. The vulnerability affects Crawlab through version 0.6.3.

  • Administrator API access and code execution.
  • Forging JWT tokens using a hard-coded secret.
  • Compromised worker nodes and system control.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Crawlab allows unauthenticated attackers to forge administrative tokens, potentially leading to code execution on worker nodes. The primary responsibility for managing and securing Crawlab likely falls on platform or infrastructure teams, in coordination with application owners if Crawlab is integrated into specific workflows. The first step should be to identify all Crawlab instances, determine their reachability and business criticality, and then assign ownership for remediation planning.

  • Platform/Infrastructure teams own remediation.
  • Verify Crawlab reachability and criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Crawlab and how is it used?

Crawlab is a distributed platform designed for managing web crawlers and spiders. Teams use it to orchestrate large-scale data extraction tasks across multiple worker nodes, relying on its web-based dashboard and API to monitor crawling jobs and distribute workloads efficiently within an infrastructure environment.

What does CVE-2026-90945 mean for software security?

This vulnerability involves 'CWE-321: Use of Hard-coded Cryptographic Key.' In Crawlab, the software uses a fixed, unchangeable secret string to sign authentication tokens. Because this secret is embedded directly into the code and cannot be modified by users, an attacker can use it to create their own legitimate-looking administrator tokens.

How does an attacker trigger this vulnerability?

An attacker triggers this by generating a forged JSON Web Token (JWT) using the known hard-coded secret. Because the system trusts any token signed with this specific key, the attacker gains immediate administrative privileges without needing a password. Note that this attack does not require any existing user account or prior interaction with the system.

Is my Crawlab instance at risk?

Halo Surface Signal indicates that Crawlab deployments often include an administrative API and web interface designed for network access. If your dashboard or API endpoint is reachable over a network—especially if exposed to the internet—it is likely vulnerable. You should treat any instance that accepts external connections as a high-priority concern.

What should I do if I am running Crawlab?

Begin by auditing your infrastructure to locate all active Crawlab instances and assess their network reachability. Since the vulnerability resides in the software logic, isolate affected systems from untrusted networks until a secure update is available. Coordinate with your platform or infrastructure teams to prioritize these instances for remediation planning.

References