CVE-2026-45091
Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.
NVD · uneditedsealed-env is a cross-stack, zero-trust secret management library for Node.js and Java/Spring Boot. In sealed-env enterprise mode, versions 0.1.0-alpha.1 through 0.1.0-alpha.3 embedded the operator's literal TOTP secret in the JWS payload of every minted unseal token. JWS payload is base64-encoded JSON, NOT encrypted. Any party who could observe a minted token (CI build logs, container env dumps, kubectl describe pod, Sentry/Rollbar stack traces, log aggregators) could decode the payload and extract the TOTP secret in plaintext. This vulnerability is fixed in 0.1.0-alpha.4.
Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.
dbcve analysis · high confidenceThe sealed-env library versions 0.1.0-alpha.1 through 0.1.0-alpha.3 in enterprise mode embedded the operator's TOTP secret in plaintext within the base64-encoded (unencrypted) JWS payload of minted unseal tokens. Anyone with access to token outputs such as logs, CI outputs, container diagnostics, or error tracking systems could decode the payload and obtain the TOTP secret.
Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.
CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.
From the vector- Attack vector
- Network
- Complexity
- Low
- Privileges
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.
dbcve checksWork through these to decide whether this CVE applies to you.
-
Identify sealed-env library versionCheck the installed version of the sealed-env package in your project (e.g., via package.json, requirements.txt, go.mod, or running npm list/pip show/equivalent). Compare it to the affected range: 0.1.0-alpha.1 through 0.1.0-alpha.3.Affected if The installed version falls within 0.1.0-alpha.1 to 0.1.0-alpha.3 inclusive.
-
Confirm enterprise mode usageInspect your sealed-env configuration or initialization code to determine whether enterprise mode is enabled. This is typically set via a configuration flag, environment variable, or code parameter at initialization.Affected if Enterprise mode is actively in use.
-
Review token outputs for JWS payloadsSearch your log files, CI pipeline outputs, container diagnostics, error tracking systems, or any other systems where unseal token output may have been written. Look for base64-encoded strings that decode to JSON containing a 'totp_secret' or similar plaintext TOTP-related field within a JWS payload structure.Affected if Any token outputs exist that contain a plaintext TOTP secret in the decoded JWS payload.
You are affected if your sealed-env version is between 0.1.0-alpha.1 and 0.1.0-alpha.3 inclusive, enterprise mode is enabled, and any unseal token outputs (logs, CI, diagnostics) may have captured the JWS payload containing the plaintext TOTP secret.
Generated from the published advisory. Verify against your own configuration.
Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.
dbcve · scopedUpgrade to sealed-env version 0.1.0-alpha.4 or later, and rotate any TOTP secrets that may have been exposed through token observations.
0.1.0-alpha.4
- Identify the sealed-env package dependency in your project (check package.json, pom.xml, or build.gradle)
- Update sealed-env to version 0.1.0-alpha.4 or later
- For Node.js: Run 'npm update sealed-env' or manually update the version in package.json then run 'npm install'
- For Java/Spring Boot: Update the dependency version in your build file and rebuild
- After upgrading, verify that minted unseal tokens no longer contain the TOTP secret in the JWS payload
- Rotate any TOTP secrets that may have been exposed during the vulnerability window
Generated from the published advisory — verify against the referenced sources before acting.
- Consultation3.0 h
- Implementation2.0 h
- Testing4.0 h
- Review / QA2.0 h
An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $3,072.
Scan for this in your stack
Free · runs locallyCheck whether your project pulls in CVE-2026-45091 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.
References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.
Primary sourcesPractitioner notes
ContributedPeer-ranked notes from engineers who’ve handled CVE-2026-45091 in production — separate from our analysis above.
The advisory tells you what broke. It rarely tells you what actually worked. If you’ve dealt with this one, that detail is what the next engineer is searching for.
- The version that genuinely resolved it — not the one the vendor claimed
- A config change or rule that shut the vector down
- A gotcha in the upgrade path that cost you an afternoon
No notes yet
Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.
A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.
- Verified mitigations, workarounds, and config changes
- Version or environment caveats, and links to real fixes
- No weaponised exploit code, or anything meant to cause harm
- No spam, self-promotion, credentials, or personal data