top of page

Anthropic Mythos HFS Vulnerability Was Patched, Then Attackers Moved In

2 hours ago
12 min read

Anthropic’s Mythos helped uncover one critical HFS flaw, but reported exploitation began soon after researchers published the complete attack chain. The Anthropic Mythos HFS vulnerability lets an unauthenticated attacker reconstruct a server secret, forge an administrator session, and reach remote code execution.

The flaw, tracked as CVE-2026-61500, affects Rejetto HTTP File Server versions 3.0.0 through 3.2.0. Rejetto fixed it in version 3.2.1 in July 2026. Horizon3 published its detailed technical analysis on September 30, and VulnCheck detected exploitation attempts the following day.

That sequence makes this more than another AI-assisted vulnerability discovery story. Mythos did not simply highlight a suspicious function. According to Horizon3, it connected separate weaknesses, modeled a reversible random-number generator, built the necessary constraints, and produced a working exploit.

The unsettling part came after disclosure. Defenders had received a patch more than two months earlier, yet vulnerable systems apparently remained reachable when the exploit mechanics became public. The central contest is therefore not Mythos against another AI model. It is accelerated vulnerability research against the slower process of identifying, updating, and verifying exposed software.

The Anthropic Mythos HFS Vulnerability Turns Randomness Into Admin Access

CVE-2026-61500 converts a weak source of randomness into an unauthenticated route to complete administrative control.

Rejetto HFS is an open-source server for sharing files over the web. Its current 3.x branch runs on Node.js and uses Koa, a JavaScript web framework, to manage web requests and sessions.

A session cookie tells a web application which authenticated user is making a request. The server signs that cookie with a secret key so an attacker cannot alter the username or privileges without invalidating the signature.

HFS created its default signing key with JavaScript’s Math.random() function. That function is suitable for ordinary randomized behavior, but it is not designed to generate cryptographic secrets.

The problem extended beyond the initial choice of generator. HFS also exposed other values from the same pseudorandom number generator during part of its login process. A pseudorandom number generator, or PRNG, produces a deterministic sequence from an internal state.

Horizon3’s technical disclosure says Mythos identified both sides of this relationship. It found the weak signing-key generation and a separate unauthenticated path that revealed observable outputs from the same sequence.

The model then reasoned that enough outputs would permit reconstruction of the generator’s state. From there, an attacker could move backward through the sequence and reproduce the values used when HFS created its signing key.

This is not the same as guessing a password through repeated login attempts. The attacker instead solves for the internal state of a deterministic system. Once that state is known, the supposedly secret key becomes reproducible.

Horizon3’s demonstrated chain begins by checking whether the built-in administrator username exists. The attacker then requests a login operation repeatedly to collect exposed Math.random() outputs.

The researchers sampled the vulnerable endpoint 12 times in their described exploit. Those observations became constraints for Z3, a Microsoft-developed satisfiability modulo theories solver.

An SMT solver determines which values satisfy a collection of logical and mathematical conditions. Here, it helped recover a state consistent with the observed random outputs and HFS’s known behavior.

The attacker can then step the recovered state backward to the server’s startup sequence. That reveals the values used to construct the cookie-signing key.

With that key, the attacker creates a correctly signed cookie claiming to represent the administrator. HFS accepts the forged session because its signature is valid, even though the real administrator never authenticated the attacker.

Administrative access provides the final link. HFS supports custom server-side code, so an administrator can configure JavaScript that runs on the host. Horizon3 used that legitimate capability to demonstrate arbitrary command execution.

The distinction matters. The dangerous behavior does not depend on injecting malformed code through an accidental parser bug. It combines forged identity with a feature that is intentionally available to administrators.

Rejetto’s fix addresses both sources of predictability. The patched version uses cryptographically secure random bytes for the signing key and a random UUID for the exposed login identifier.

Operators should install the HFS 3.2.1 release or a newer stable version. Setting a strong explicit signing key can reduce one part of the risk, but upgrading removes the documented chain and remains the appropriate response.

Mythos Found a Chain That Human Reviewers Might Have Abandoned

The important Mythos result was not identifying `Math.random()`, but proving that several ordinary-looking mistakes formed a practical exploit.

Static-analysis tools have warned developers about weak random-number generators for years. A scanner can search for Math.random() near authentication code and flag the line for review.

That observation alone does not establish remote compromise. A researcher still needs to determine whether an attacker can observe related outputs, reconstruct the generator, recover the exact key, forge the correct cookie format, and turn authentication into meaningful impact.

Each step adds work and uncertainty. That often changes whether a finding receives further investigation, especially when researchers must choose among many possible leads.

Horizon3 says Mythos handled that longer reasoning path. Its specialized cryptographic-analysis agent noticed that HFS consumed three random outputs while creating the signing key at startup.

The model also identified a login path that returned full-precision values produced by the same generator. It recognized that the cookie was signed but not encrypted, allowing the client to read its own session data.

Mythos then connected those facts to V8’s xorshift128+ implementation. V8 is the JavaScript engine used by Node.js, and xorshift128+ maintains a reversible internal state.

Reversibility does not automatically make every application using the generator exploitable. The attacker still needs enough useful observations and a way to correlate them with the secret-generating sequence.

HFS supplied both conditions. It exposed consecutive values through the login flow, while the signing key came from the same generator when the process started.

The model proposed using Z3 to recover the state rather than attempting a naive search across every possible key. It also identified an existing cookie and signature as an offline verification mechanism.

That verification step is significant. A recovered candidate can be tested locally against a legitimate cookie’s message authentication code. The attacker does not need to send every candidate to the target and generate obvious failed requests.

According to Horizon3, Mythos created the working proof of concept and demonstrated arbitrary command execution. Human researchers reviewed the result before disclosure, which is essential when a model’s analysis can contain subtle errors.

Anthropic’s broader Mythos capability report describes a similar emphasis on complete exploitation. The company argues that producing a working exploit helps distinguish consequential vulnerabilities from crashes or suspicious code that lacks practical impact.

That approach can improve defensive triage. A confirmed route to administrator access deserves different treatment from an isolated warning with no accessible trigger.

It also lowers the economic barrier to pursuing unusual vulnerability classes. Horizon3’s researchers said cryptographic findings can be deprioritized because proving them requires specialized mathematical knowledge and substantial time.

An AI system that completes those steps can make previously uneconomical research viable. The set of bugs worth investigating grows when the marginal cost of building and testing an exploit falls.

The Mythos HFS exploit illustrates that shift clearly. No single ingredient was unprecedented. Weak randomness, exposed generator outputs, signed cookies, and privileged administrative functions are established security concepts.

The change lies in synthesis. Mythos reportedly followed the relationship across files, frameworks, mathematical behavior, and application features without requiring researchers to prescribe each intermediate step.

That is also why simplistic claims about AI “finding a bug” miss the real pressure. Discovery has value, but exploit construction determines whether a finding becomes an urgent operational problem.

Public Disclosure Collided With a Slow Patch Cycle

The patch existed before the full exploit analysis, yet public-facing HFS systems reportedly remained vulnerable when the method became easier to reproduce.

Rejetto released version 3.2.1 on July 13, 2026. CVE records identify versions 3.0.0 through 3.2.0 as affected.

Horizon3 waited until September 30 to publish its detailed breakdown. That delay gave administrators time to update without handing attackers a complete explanation of the vulnerability.

The disclosure included the important mechanics. It described the random-number leak, state reconstruction, key recovery, forged administrator session, and transition to code execution.

VulnCheck began detecting attempted exploitation on October 1, according to observed attack traffic. The initial activity reportedly involved infrastructure hosted in China targeting vulnerable systems in the United States.

Subsequent requests came from two US addresses in the same subnet, which appeared to operate as proxies. Researchers also reported targeting against systems in Japan.

These observations support active exploitation attempts, but they do not establish the attacker’s identity or government affiliation. Hosting location and proxy location are weak attribution signals.

They also do not reveal how many systems were compromised. A detection can show that someone sent exploit-related traffic without proving that the target accepted a forged session or executed a command.

Even with those limits, the timing matters. The first observed activity followed the public technical explanation by roughly one day.

That does not prove attackers independently reproduced every mathematical step during that period. They may have developed the technique earlier, adapted disclosed material, or obtained enough information from existing vulnerability records.

The operational lesson remains the same. Once detailed exploit information becomes public, defenders should assume that capable actors can translate it into scanning and attack traffic quickly.

Anthropic’s disclosure policy aims to balance those competing needs. It generally targets notification to maintainers, a 90-day disclosure period, and human review of AI-originated reports.

The policy says Anthropic normally waits 45 days after a patch before publishing full technical details. That buffer is intended to give downstream users time to deploy fixes.

CVE-2026-61500 had a longer interval between its July patch and Horizon3’s September analysis. The appearance of vulnerable systems after that interval shows why disclosure timing cannot compensate for incomplete asset visibility.

A server may be overlooked because it was deployed for a short-term transfer and never entered an inventory. A container may remain pinned to an older image. A self-hosted service can also sit behind a forgotten port-forwarding rule.

HFS attracts precisely these lightweight use cases. Its accessibility makes file sharing easy, but it can also encourage deployments outside centrally managed infrastructure.

The software’s history makes that concern concrete. An earlier HFS flaw affecting the older 2.x branch entered CISA’s Known Exploited Vulnerabilities catalog in 2024.

That older issue was a different vulnerability in a different codebase. HFS 3.x was rewritten in TypeScript, while the 2.x branch used Delphi.

The precedent does not mean every HFS installation is compromised. It does show that internet-exposed file servers are attractive targets, especially when exploitation leads directly to code execution.

Patching therefore needs a verification step. Security teams should not close the ticket when an update is assigned. They should confirm that every reachable instance reports a fixed version and that old containers or binaries no longer answer requests.

The Real Contest Is AI Discovery Versus Remediation Speed

Mythos raises the tempo of security research, but an organization’s exposure still depends on how quickly it can locate and update its systems.

Security programs often measure vulnerability management through counts. Teams report how many findings they opened, how many patches they deployed, or what percentage met a service-level target.

CVE-2026-61500 highlights a more consequential interval. The important clock starts when a fix becomes available and ends when every exposed vulnerable instance is either updated, isolated, or removed.

AI-assisted research compresses the time needed to turn source code into a validated attack path. Public disclosure then makes that path cheaper for additional researchers and attackers to reproduce.

The patching process does not automatically accelerate at the same rate. It still depends on ownership records, maintenance windows, testing, approval, deployment, and confirmation.

This creates an asymmetric contest. Researchers can parallelize analysis across repositories, while defenders must handle each affected production system within its business context.

The Anthropic Mythos HFS vulnerability also demonstrates why severity scores alone are insufficient. A critical rating identifies potential impact, but it does not tell an organization whether the vulnerable application is reachable from the internet.

Conversely, a small file-sharing server may receive little attention because it supports only a few users. If it permits unauthenticated remote code execution, its modest business profile does not reduce its usefulness as an entry point.

The proper response begins with discovery. Teams should search software inventories, container registries, cloud workloads, endpoint deployments, and externally accessible services for Rejetto HFS.

They should distinguish the 3.x branch from older HFS versions because the fixes and vulnerability mechanisms differ. Any supported 3.x installation should run version 3.2.1 or later, although the newest stable release is preferable.

Network controls provide another layer. An HFS instance intended for a limited group should not remain open to the entire internet when access can be restricted through a VPN, allowlist, or authenticated gateway.

Those controls do not replace the upgrade. A compromised trusted endpoint, configuration mistake, or future network change can expose a service that administrators believed was isolated.

Teams should also review server logs around the public disclosure date. Repeated calls to authentication endpoints, unexpected administrator sessions, configuration changes, and unfamiliar server-side code deserve investigation.

A successful attacker might modify more than the visible HFS configuration. Remote code execution can allow persistence through operating-system accounts, scheduled tasks, startup scripts, or additional services.

For that reason, patching a confirmed compromised host is not enough. Responders should isolate it, preserve evidence, rotate relevant credentials, assess connected resources, and rebuild when system integrity cannot be established.

The defensive implications extend beyond HFS. Developers should treat general-purpose pseudorandom generators as unacceptable sources for authentication secrets, reset tokens, cryptographic nonces, and session identifiers.

Code review should examine shared-state relationships, not only individual calls. A secure secret can still become predictable if the same generator leaks correlated outputs elsewhere.

Framework defaults require similar scrutiny. Developers sometimes assume that a library will make an insecure input safe. A signing framework can protect cookie integrity only when the supplied signing key remains secret and unpredictable.

AI-assisted analysis is well suited to following these cross-file relationships. Models can search call sites, trace data flow, compare framework behavior, and test whether a theoretical weakness reaches a privileged operation.

That advantage does not remove the need for human validation. A generated exploit can misread a version, omit an environmental assumption, or demonstrate behavior that does not generalize beyond a test harness.

The strongest workflow combines machine scale with accountable review. AI proposes and tests attack chains, while experienced researchers reproduce the result, assess severity, coordinate remediation, and control disclosure.

What the Mythos HFS Exploit Does Not Prove

One successful exploit chain shows a meaningful capability, but it does not establish that Mythos will reliably find every critical vulnerability.

Horizon3’s report is a case study produced by an organization participating in Anthropic’s Project Glasswing. The researchers used a custom harness that ran specialized agents in parallel across the HFS codebase.

That context matters. The result does not represent an unassisted consumer chatbot receiving a repository and instantly compromising it.

The harness shaped the investigation by assigning agents to particular vulnerability classes. Human researchers also selected the target, reviewed the findings, and handled responsible disclosure.

Mythos nevertheless appears to have contributed more than autocomplete or a generic security checklist. According to the researchers, it independently linked the weak PRNG, output leak, session format, backward state reconstruction, and administrative code-execution feature.

The published evidence supports the HFS finding because a working exploit demonstrated the chain. It provides less information about false positives, total compute, unsuccessful runs, and findings discarded during the broader analysis.

Those missing denominators limit broad productivity comparisons. A model that finds one exceptional vulnerability after many expensive attempts presents a different operational proposition from one that succeeds consistently.

The case also does not show that AI alone caused the rapid exploitation. Attackers have long moved quickly after proof-of-concept code and technical write-ups became public.

Conventional scanners, diffing tools, exploit frameworks, and human reverse engineering already support that workflow. AI adds speed and accessibility, but it joins an existing offensive toolchain.

Nor does a source location establish attribution. The reported attacks used infrastructure in China and the United States, but proxies and compromised hosts routinely obscure where an operator sits.

Claims about a nation-state campaign would require additional evidence, including tooling overlap, infrastructure history, victim selection, and behavior after access.

There is also uncertainty about the scale of successful exploitation. Published reporting described a small number of detected requests against real vulnerable systems.

That is sufficient to justify urgent patching. It is not sufficient to estimate a global infection count or claim a widespread campaign.

Defenders should resist both extremes. Dismissing Mythos as marketing ignores a validated, technically interesting exploit. Treating one case as proof of universal autonomous hacking exaggerates what the public evidence supports.

The balanced conclusion is narrower and still important. An AI-assisted research system helped specialists turn a subtle cryptographic design error into an end-to-end exploit that reached remote code execution.

That capability expands which findings researchers can pursue economically. It also increases the value of reducing the delay between patch availability and verified deployment.

Three Signals Will Show Whether Defenders Can Keep Up

The next test is whether exploitation expands, patch adoption improves, and AI-originated disclosures remain manageable for software maintainers.

The first signal is the scope of observed attacks. More source addresses, exploit variations, post-compromise payloads, or affected organizations would strengthen the conclusion that CVE-2026-61500 has moved beyond opportunistic testing.

A continued trickle of simple probes would support a narrower interpretation. It would suggest that attackers are experimenting with the public technique without yet building a sustained campaign.

The second signal is whether Rejetto HFS operators actually remove vulnerable versions. Internet measurements and incident reports can reveal whether installations running 3.0.0 through 3.2.0 persist after warnings circulate.

Rapid decline would show that maintainers, security vendors, and administrators converted disclosure into action. Long-lived exposure would confirm that inventory and deployment remain the limiting factors.

The third signal is the quality and volume of later Project Glasswing disclosures. Anthropic says AI-originated vulnerability reports receive human review and coordinated handling before publication.

A steady flow of reproducible, high-impact findings would support the argument that Mythos changes research economics. A flood of low-value reports would instead burden open-source maintainers and weaken confidence in the process.

This is the larger consequence of the Anthropic Mythos HFS vulnerability. Better discovery creates defensive value only when maintainers can absorb reports and users deploy the resulting fixes.

Security teams should update affected HFS servers now, verify the deployed version, restrict unnecessary exposure, and investigate suspicious activity after September 30. Then they should ask a harder question: if the next AI-assisted exploit arrives with the same compressed timeline, can their asset inventory produce an answer before attackers do?

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page