Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-81697— openssl_encrypt before 1.4.9 KDF Downgrade via CWD-relative Configuration

Quick assessment

Affected
jahlives openssl_encrypt
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Tobi OpenSSL Encrypt是Tobi个人开发者的一款基于 Python 的文件加密工具。 Tobi OpenSSL Encrypt 1.4.8及之前版本存在权限许可和访问控制问题漏洞,该漏洞源于crypt_settings.py中的配置文件解析缺陷,配置文件被改为从当前工作目录读取,攻击者可放置恶意配置文件降级加密强度,绕过弱KDF预检,进而导致离线暴力破解攻击。

CVSS 5.5 · Medium EPSS 0.15% · P4

Affected Version Matrix 2

VendorProduct Version RangeStatus
jahlives openssl_encrypt < 1.4.9 affected
1.4.9 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-81697

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
openssl_encrypt before 1.4.9 KDF Downgrade via CWD-relative Configuration
Source: CVE Program / CVE List V5
Vulnerability Description
openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 contain a CWD-relative configuration file resolution flaw in crypt_settings.py, where CONFIG_FILE (originally the absolute per-user path ~/.crypt_settings.json) is reassigned at line 84 to the bare relative name 'crypt_settings.json'. As a result, the legacy Tk GUI's SettingsTab reads and writes KDF settings from crypt_settings.json in the process launch (current working) directory instead of the user's home directory. An attacker who plants a malicious crypt_settings.json (e.g. sha256:1 with all memory-hard KDFs disabled) can silently downgrade encryption performed in that GUI session to roughly one hash round, bypassing the weak-KDF preflight and enabling offline brute-force attacks against the resulting ciphertext. Fixed in 1.4.9.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
不可信的搜索路径
Source: CVE Program / CVE List V5
Vulnerability Title
Tobi OpenSSL Encrypt 权限许可和访问控制问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Tobi OpenSSL Encrypt是Tobi个人开发者的一款基于 Python 的文件加密工具。 Tobi OpenSSL Encrypt 1.4.8及之前版本存在权限许可和访问控制问题漏洞,该漏洞源于crypt_settings.py中的配置文件解析缺陷,配置文件被改为从当前工作目录读取,攻击者可放置恶意配置文件降级加密强度,绕过弱KDF预检,进而导致离线暴力破解攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
jahlives openssl_encrypt 0 ~ 1.4.9 -

II. Public POCs for CVE-2026-81697

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-81697

登录查看更多情报信息。

Vendor Advisories for CVE-2026-81697 (2)

Same Patch Batch · jahlives · 2026-08-27 · 36 CVEs total

CVE-2026-81707 9.8 CRITICAL openssl_encrypt before 1.4.9 ANSI Escape Injection via Identity Email
CVE-2026-81702 9.8 CRITICAL openssl_encrypt before 1.4.9 Key Substitution via Identity Load
CVE-2026-81700 9.8 CRITICAL openssl_encrypt before 1.4.9 GPG Signature Verification Bypass
CVE-2026-81701 9.8 CRITICAL openssl_encrypt before 1.4.9 Arbitrary Code Execution via unsigned plugin
CVE-2026-81683 8.4 HIGH openssl_encrypt before 1.4.9 Plaintext Private Key Storage
CVE-2026-81719 7.8 HIGH openssl_encrypt before 1.4.9 Remote Code Execution via Plugin
CVE-2026-81688 7.5 HIGH openssl_encrypt before 1.4.9 Plaintext Confirmation Oracle via SHA-256
CVE-2026-81704 7.5 HIGH openssl_encrypt before 1.4.9 Weak Key Derivation via D-Bus
CVE-2026-81691 7.5 HIGH openssl_encrypt before 1.4.9 Credential Leakage via Unvalidated Server URLs
CVE-2026-81721 7.5 HIGH openssl_encrypt before 1.4.9 Denial of Service via KDF
CVE-2026-81698 7.5 HIGH openssl_encrypt before 1.4.9 Shell Injection via info command
CVE-2026-81693 7.5 HIGH openssl_encrypt before 1.4.9 Denial of Service via QR total field
CVE-2026-81705 7.5 HIGH openssl-encrypt before 1.4.9 Password Cleartext Leak via Debug
CVE-2026-81689 7.5 HIGH openssl_encrypt before 1.4.9 Weak Pepper Key Derivation
CVE-2026-81699 7.5 HIGH openssl_encrypt before 1.4.9 Denial of Service via unbounded KDF cost
CVE-2026-81692 7.5 HIGH openssl_encrypt before 1.4.9 Denial of Service via STREAMINFO
CVE-2026-81718 7.5 HIGH openssl_encrypt before 1.4.9 Weak Cryptographic Parameters
CVE-2026-81690 7.3 HIGH verify-usb before 1.4.9 Symlink Directory Traversal Code Execution
CVE-2026-81714 7.0 HIGH openssl_encrypt before 1.4.9 Plugin Signing Trust Anchor Enrollment Bypass
CVE-2026-81706 6.8 MEDIUM openssl_encrypt before 1.4.9 Key Substitution via Identity Shadowing

Showing top 20 of 36 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-81697

No comments yet


Leave a comment