PT-2025-41496 · Allstar+1 · Allstar+1

Adamkorcz

·

Published

2025-10-09

·

Updated

2025-10-27

·

CVE-2025-61926

CVSS v4.0

4.6

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U
Name of the Vulnerable Software and Affected Versions Allstar versions prior to 4.5
Description Allstar is a GitHub App used for setting and enforcing security policies. A flaw exists in the Reviewbot component where inbound webhook requests were validated against a hard-coded, shared secret. This secret token was compiled into the Allstar binary and could not be configured during runtime. Deployments using Reviewbot validated requests with the same secret unless the operator modified the source code and rebuilt the component. This expectation was not documented and easily overlooked. Deployments that have not enabled or exposed the Reviewbot endpoint are not affected.
Recommendations Update to version 4.5 or later. If the Reviewbot endpoint is not in use, no action is required.

Exploit

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2025-61926
GHSA-33F4-MJCH-7FPR
GO-2025-4018
OPENSUSE-SU-2025:15666-1
SUSE-SU-2025:3799-1

Affected Products

Allstar
Reviewbot