PT-2026-33365 · Unknown · Cryptomator
Published
2026-04-16
·
Updated
2026-04-17
·
CVE-2026-33472
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cryptomator version 1.19.1
Description
A logic flaw exists in the
getAuthority() function of the CheckHostTrustController. The method hardcodes the URI scheme based on the port number, which results in HTTPS URLs using port 80 producing the same authority string as HTTP URLs. This bypasses the consistency check and HTTP block validation. An attacker with write access to a cloud-synced vault.cryptomator file can configure the apiBaseUrl and authEndpoint variables to use HTTPS with port 80 to pass auto-trust validation, while the tokenEndpoint variable uses plaintext HTTP. This allows the vault to be auto-trusted without a user prompt, enabling a network-positioned attacker to intercept the OAuth token exchange and access the Cryptomator Hub API as the victim.Recommendations
Update to version 1.19.2.
Exploit
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cryptomator