CVE-2026-52539 | Outstatic up to 2.1.9 JWT Signing Secret constants.ts OST_TOKEN_SECRET permission

SecurityVulns

A vulnerability classified as critical was found in Outstatic up to 2.1.9. Affected is an unknown function of the file packages/outstatic/src/utils/constants.ts of the component JWT Signing Secret. Such manipulation of the argument OST_TOKEN_SECRET leads to permission issues.

This vulnerability is traded as CVE-2026-52539. The attack may be launched remotely. There is no exploit available.VulDB Recent EntriesRead More