Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-46513— Frogman: API tokens stored in plaintext

Quick assessment

Affected
mwtcmi frogman
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Michael White Frogman是Michael White个人开发者的一款通过 MCP 和 HTTP API 实现无头 PBX 控制的软件。 Michael White Frogman 1.6.2之前版本存在信任管理问题漏洞,该漏洞源于Frogman将API令牌以原始字符串形式存储,并通过比较存储原始值来验证X-Frogman-Token标头,可能允许数据库读取访问恢复可重用的活动令牌,达到其分配的权限级别,包括管理员权限。

CVSS 7.4 · High EPSS 0.43% · P35

Affected Version Matrix 1

VendorProduct Version RangeStatus
mwtcmi frogman < 1.6.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-46513

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Frogman: API tokens stored in plaintext
Source: CVE Program / CVE List V5
Vulnerability Description
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, Frogman stored API tokens generated by Tools/CreateApiToken.php:33-36 as raw bin2hex(random_bytes(32)) strings in oc_api_tokens, and Frogman.class.php:78 authenticated the X-Frogman-Token header by comparing it with the stored raw value, allowing database read access to recover reusable active tokens at their assigned permission level, including admin. This issue is fixed in version 1.6.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
明文存储口令
Source: CVE Program / CVE List V5
Vulnerability Title
Michael White Frogman 信任管理问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Michael White Frogman是Michael White个人开发者的一款通过 MCP 和 HTTP API 实现无头 PBX 控制的软件。 Michael White Frogman 1.6.2之前版本存在信任管理问题漏洞,该漏洞源于Frogman将API令牌以原始字符串形式存储,并通过比较存储原始值来验证X-Frogman-Token标头,可能允许数据库读取访问恢复可重用的活动令牌,达到其分配的权限级别,包括管理员权限。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
mwtcmi frogman < 1.6.2 -

II. Public POCs for CVE-2026-46513

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 9228 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-46513

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-46513 (2)

Vendor Advisories for CVE-2026-46513 (1)

Same Patch Batch · mwtcmi · 2026-07-16 · 4 CVEs total

CVE-2026-46512 9.9 CRITICAL Frogman: Dialplan template parameters interpolated into extensions_custom.conf without esc
CVE-2026-46514 6.5 MEDIUM Frogman: Plaintext passwords and secrets persisted to audit log
CVE-2026-46515 Frogman: Multiple read-tier tools expose admin-grade data and arbitrary GraphQL execution

IV. Related Vulnerabilities

V. Comments for CVE-2026-46513

No comments yet


Leave a comment