Loading vulnerability details...
| Property | Value |
|---|---|
| Advisory ID | SGZ-2026-C946D |
| Severity | HIGH |
| CWE | CWE-319 |
| Confidence | 90% |
| Category | crypto_misuse |
| Exploitability | confirmed |
| Package | adios2_seal_keygen@latest (github) |
| Location | plugins/operators/adios2_seal_keygen.py:22-27 |
| Attack Vector | LOCAL |
| Attack Complexity | LOW |
| Privileges Required | NONE |
| Discovered By | SafeGuard Zero-Day AI Discovery Engine |
The script writes the generated Curve25519 private key to a file using the default open() mode, which inherits the process umask and may create a world‑readable file. It also prints the secret key in hex to standard output. An attacker who can execute the script or capture its output can obtain the private key, enabling decryption of any data sealed with the corresponding public key.
The vulnerability was identified in the file plugins/operators/adios2_seal_keygen.py at lines 22-27 within the adios2_seal_keygen package (version latest). Any code path that invokes these functions inherits this vulnerability.
File: plugins/operators/adios2_seal_keygen.py (lines 22-27)
sk = nacl.public.PrivateKey.generate()
open(a.secret_key_file, "wb").write(sk.encode())
...
print(f"Secret key: {a.secret_key_file}\n hex: {sk.encode(nacl.encoding.HexEncoder).decode()}")
The code above demonstrates the vulnerable pattern. This code is executed at runtime and can be directly exploited by an attacker with the appropriate access level.
Run the script with the 'generate' command and capture stdout or read the generated secret_key_file if its permissions are too permissive (e.g., 0644). The attacker then obtains the private key.
Compromise of the private key allows decryption of sealed data and impersonation of the key owner.
Write the private key using a restrictive mode (e.g., os.open with 0o600) and avoid printing the key to stdout. Use file mode 'xb' to prevent overwriting existing files and set explicit permissions after creation.
Advisory: SGZ-2026-C946D | Source: SafeGuard Zero-Day AI Discovery | Status: Candidate
This vulnerability was autonomously discovered by SafeGuard's AI-powered Zero-Day Discovery engine using TAOR (Think-Act-Observe-Repeat) agentic analysis on the package source code. It is not yet tracked in any public vulnerability database (CVE, NVD, GHSA, OSV). This finding should be triaged by a security engineer and, if confirmed, reported upstream to the package maintainer.
| Property | Value |
|---|---|
| Advisory ID | SGZ-2026-C946D |
| Severity | HIGH |
| CWE | CWE-319 |
| Confidence | 90% |
| Category | crypto_misuse |
| Exploitability | confirmed |
| Package | adios2_seal_keygen@latest (github) |
| Location | plugins/operators/adios2_seal_keygen.py:22-27 |
| Attack Vector | LOCAL |
| Attack Complexity | LOW |
| Privileges Required | NONE |
| Discovered By | SafeGuard Zero-Day AI Discovery Engine |
The script writes the generated Curve25519 private key to a file using the default open() mode, which inherits the process umask and may create a world‑readable file. It also prints the secret key in hex to standard output. An attacker who can execute the script or capture its output can obtain the private key, enabling decryption of any data sealed with the corresponding public key.
The vulnerability was identified in the file plugins/operators/adios2_seal_keygen.py at lines 22-27 within the adios2_seal_keygen package (version latest). Any code path that invokes these functions inherits this vulnerability.
File: plugins/operators/adios2_seal_keygen.py (lines 22-27)
sk = nacl.public.PrivateKey.generate()
open(a.secret_key_file, "wb").write(sk.encode())
...
print(f"Secret key: {a.secret_key_file}\n hex: {sk.encode(nacl.encoding.HexEncoder).decode()}")
The code above demonstrates the vulnerable pattern. This code is executed at runtime and can be directly exploited by an attacker with the appropriate access level.
Run the script with the 'generate' command and capture stdout or read the generated secret_key_file if its permissions are too permissive (e.g., 0644). The attacker then obtains the private key.
Compromise of the private key allows decryption of sealed data and impersonation of the key owner.
Write the private key using a restrictive mode (e.g., os.open with 0o600) and avoid printing the key to stdout. Use file mode 'xb' to prevent overwriting existing files and set explicit permissions after creation.
Advisory: SGZ-2026-C946D | Source: SafeGuard Zero-Day AI Discovery | Status: Candidate
This vulnerability was autonomously discovered by SafeGuard's AI-powered Zero-Day Discovery engine using TAOR (Think-Act-Observe-Repeat) agentic analysis on the package source code. It is not yet tracked in any public vulnerability database (CVE, NVD, GHSA, OSV). This finding should be triaged by a security engineer and, if confirmed, reported upstream to the package maintainer. This vulnerability involves weaknesses in
This high-severity vulnerability could allow attackers to gain unauthorized access, execute arbitrary code, or compromise data integrity. Prompt remediation is strongly recommended.
Isolate affected systems from untrusted networks until patching is complete
Implement enhanced monitoring for exploitation attempts and unusual behavior