Sceawere
Vulnerability Detail
CVE-2026-108584UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
FunnyWolf Viper Hard-Coded Credentials
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 4h ago
- Vendor
- FunnyWolf
- Product
- Viper
- Attack Type
- Hard-coded Credentials
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A security flaw has been discovered in FunnyWolf Viper up to 3.1.11. The affected element is an unknown function of the file /root/viper/.git/config. Performing a manipulation results in hard-coded credentials. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-11T13:17:13.557Z",
"pubdate": "2026-10-11T13:17:13.557Z",
"executiveSummary": "A critical security vulnerability has been identified in FunnyWolf Viper versions up to and including 3.1.11, stemming from the exposure of hard-coded credentials within the application's environment.\nThe vulnerability is classified as an improper storage of sensitive information, specifically involving credentials embedded within the /root/viper/.git/config file.\nThis flaw enables unauthorized actors to gain unauthorized access to the application or underlying system.\nThe risk is significantly elevated due to the public availability of functional exploit code, which lowers the barrier to entry for potential attackers.\nSuccessful exploitation can be performed remotely, allowing an adversary to compromise the integrity, confidentiality, and availability of the affected system without prior authentication.\nImmediate action is required to remediate this configuration flaw, as it poses a severe threat to any deployment where the default installation configuration remains intact.",
"technicalDetails": "The vulnerability resides in the improper management and exposure of sensitive configuration data within the FunnyWolf Viper application, specifically affecting versions 3.1.11 and earlier.\nThe root cause is the presence of hard-coded, sensitive credentials located within the /root/viper/.git/config file. This file, typically intended for Git configuration management, inadvertently contains security-critical authentication material that is accessible to unauthorized users if the directory is reachable or exposed.\nThe attack flow commences with the adversary identifying an instance of FunnyWolf Viper exposed to the network. Due to the nature of the misconfiguration, the attacker does not require valid credentials or high-level privileges to initiate the exploitation process.\nThe adversary attempts to access the sensitive /root/viper/.git/config file. If the web server or application deployment is incorrectly configured to serve static files from the /root/ directory, or if the .git directory is improperly exposed through the web root, the attacker can retrieve the file contents directly via HTTP GET requests.\nUpon successful retrieval of the configuration file, the attacker parses the file to extract the hard-coded credentials. These credentials often include administrative passwords, API keys, or database access tokens necessary for managing the FunnyWolf Viper instance.\nWith these credentials in hand, the attacker can authenticate as a legitimate user, potentially with administrative privileges, to the application interface. The impact of this post-exploitation phase includes full control over the Viper framework, access to underlying server resources, the ability to pivot into internal networks, and the potential for complete system compromise or data exfiltration.\nBecause the exploit is publicly available, the complexity of carrying out this attack is low, and the requirement for technical sophistication is minimal, increasing the likelihood of automated scanning and mass exploitation attempts by malicious actors."
}