GHSA-w72w-9qmj-c9qm
AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secrets
Quick fix
GHSA-w72w-9qmj-c9qm — github.com/anycable/anycable: upgrade to the fixed version with the command below.
go get github.com/anycable/anycable@v1.6.15Details
### Summary The telemetry subsystem embeds a hardcoded auth token (`"secret"`) in the public source and transmits raw CLI arguments—including `--secret`, `--jwt_secret`, and `--http_rpc_secret` values—to a third-party telemetry endpoint.
### Details In `telemetry/config.go` line 12, `var authToken = "secret"` is committed in the public repository and used to authenticate to `https://telemetry.anycable.io`. In `telemetry/telemetry.go`, `clusterFingerprint()` (line 320) calls both `anycableFileConfig(c.ConfigFilePath)` (line 333), which reads the full TOML config file contents, and `anycableCLIArgs()` (line 402), which reads `os.Args[1:]` verbatim—including any `--secret=...`, `--jwt_secret=...`, `--http_rpc_secret=...` arguments. Both raw values are passed to `generateDigest()` (line 373), meaning the actual secret strings flow through the code path and are included in telemetry data sent to the third-party server. Since the hardcoded `authToken = "secret"` is public, any attacker who can perform DNS hijacking or is positioned on the network path can intercept and read the telemetry payload containing operator credentials.
### PoC 1. Read `telemetry/config.go` in the public repo to find `authToken = "secret"`. 2. Set up a DNS spoof for `telemetry.anycable.io` pointing to an attacker-controlled server. 3. Start anycable-go with `--secret=my-production-secret`. 4. The server sends a POST to the attacker's endpoint with the telemetry JSON payload. The `clusterFingerprint` field contains data derived from raw `os.Args` including `--secret=my-production-secret`.
### Impact In MITM/DNS-hijack scenarios, production secrets (JWT secrets, broadcast keys, RPC auth) are exposed to third parties. The hardcoded `authToken = "secret"` provides no protection since it is known to anyone reading the open-source code.
### Fix 1. Remove the hardcoded `authToken` from source; generate or require operator configuration at build time or deployment time. 2. Remove `anycableCLIArgs()` from the fingerprint computation, or sanitize it to exclude values of secret-bearing flags before hashing. 3. Add a documented opt-out mechanism for telemetry.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.6.15go get github.com/anycable/anycable@v1.6.15