1. Critical Hardcoded JWT Secret Exposes socfortress CoPilot to Full Admin Takeover via CVE-2026-42869
A critical authentication vulnerability has been identified in socfortress CoPilot, affecting all versions prior to 0.1.57. The flaw, tracked as CVE-2026-42869 and classified under CWE-287 (Improper Authentication), stems from a hardcoded JWT secret embedded within the software. This weakness allows remote attackers to...