Anthropic Mythos AI Exposes Critical Rejetto HFS Flaw
An advanced artificial intelligence designed specifically for vulnerability research has successfully identified a profound architectural flaw within the Rejetto HFS file server. This devastating vulnerability effectively transmutes several seemingly innocuous random number leaks into absolute administrative access and subsequent remote code execution. The Horizon3 security research team comprehensively demonstrated how Anthropic’s Mythos model autonomously synthesized a fully functional attack chain targeting HFS 3.x architectures.
Deconstructing CVE-2026-61500 and the Math.random() Failure
This critical vulnerability, formally designated CVE-2026-61500, commands a severe 9.3 rating on the CVSS 4.0 scale. Rejetto HFS versions spanning from 3.0.0 directly through 3.2.0 are inherently vulnerable. The primary developer proactively remediated the breach in version 3.2.1 on July 13th; consequently, by the time the comprehensive technical autopsy was published, the vulnerability had mercifully ceased to be a zero-day threat.
The fundamental root of this catastrophe resided within the mechanism responsible for generating the cryptographic signature key for session cookies. Inexplicably, HFS fabricated this vital secret utilizing the standard JavaScript Math.random() function, a utility fundamentally devoid of the cryptographic rigor required for secure operations. Within the Node.js environment, the V8 JavaScript engine’s generator relies upon the highly predictable xorshift128+ algorithm. Exacerbating this weakness, the server simultaneously, and inadvertently, leaked tangential values originating from this identical continuous stream back to the client during the initiation of the SRP login protocol.
Mythos AI: Synthesizing the Exploit Chain
The Mythos AI astutely correlated these two distinct operational quirks and autonomously proposed a methodology to definitively reconstruct the internal state of the random number generator. During the practical demonstration, the simulated attacker interacted precisely 12 times with the unauthenticated login function, meticulously harvesting the sequential Math.random() outputs. These harvested values were then strategically fed into the formidable Z3 theorem prover. The successfully recovered internal state empowered the attacker to computationally rewind the generator’s state space, thereby precisely calculating the initial cryptographic key fabricated during the HFS server’s startup sequence.
Armed with this meticulously reconstructed key, the adversary can effortlessly forge a bespoke session cookie bearing the ‘administrator’ moniker, seamlessly bypassing all authentication checks as a fully legitimate session. Subsequently, HFS unwittingly exposes its administrative API. This API inherently features a server_code parameter, explicitly designed to facilitate the execution of server-side JavaScript. Through this elegant progression, a mere authentication bypass irrevocably mutates into absolute, unconstrained remote code execution.
From Theoretical Discovery to Active Exploitation
Anthropic rigorously restricts direct access to the formidable Mythos model, choosing instead to cultivate Project Glasswing in close collaboration with vetted, external security partners. While the model has historically unearthed hundreds of CVEs, the practical, real-world exploitation of its specific discoveries has remained relatively infrequent. However, in the Rejetto HFS scenario, the neural network not merely identified the cryptographically weak generator; it autonomously conceptualized the precise mathematical strategy necessary to escalate the flaw into a devastating, functional exploit.
Following the publication of these intricate technical details, the theoretical risk rapidly spilled out of the controlled laboratory environment. Security firm VulnCheck detected active attempts to exploit CVE-2026-61500 beginning October 1st and subsequently enshrined the vulnerability within its KEV (Known Exploited Vulnerabilities) catalog. The company estimates that approximately 100 vulnerable HFS instances currently remain exposed to the public internet, urgently recommending that administrators managing antiquated versions immediately migrate to version 3.2.1 or newer.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.