PT-2025-41496 · Allstar+1 · Allstar+1
Adamkorcz
·
Published
2025-10-09
·
Updated
2025-10-27
·
CVE-2025-61926
CVSS v4.0
4.6
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U |
Name of the Vulnerable Software and Affected Versions
Allstar versions prior to 4.5
Description
Allstar is a GitHub App used for setting and enforcing security policies. A flaw exists in the Reviewbot component where inbound webhook requests were validated against a hard-coded, shared secret. This secret token was compiled into the Allstar binary and could not be configured during runtime. Deployments using Reviewbot validated requests with the same secret unless the operator modified the source code and rebuilt the component. This expectation was not documented and easily overlooked. Deployments that have not enabled or exposed the Reviewbot endpoint are not affected.
Recommendations
Update to version 4.5 or later.
If the Reviewbot endpoint is not in use, no action is required.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Allstar
Reviewbot