THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-w72w-9qmj-c9qm (medium) — AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secrets

[GHSA] GHSA-w72w-9qmj-c9qm (medium) — AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secrets

highgithub_advisoriesPublished 2026-09-18

GHSA-w72w-9qmj-c9qm Severity: medium CVE: CVE-2026-63406

AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secrets

### Summary The telemetry subsystem embeds a hardcoded auth token (`"secret"`) in the public source and transmits raw CLI arguments—including `--secret`, `--jwt_secret`, and `--http_rpc_secret` values—to a third-party telemet

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-w72w-9qmj-c9qm