Information ExposureWeakness · CWE-200

CVE-2026-45091

CRITICAL · 9.1 CVSS v3.1 Published 2026-05-12
Mitigation only
No fix yet — a mitigation exists. There is no fixed release. A documented workaround reduces exposure in the meantime.
See remediation →
100/100
Remediation priority · Urgent
Remotely reachable No privileges Zero-click

Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.

NVD · unedited
sealed-env is a cross-stack, zero-trust secret management library for Node.js and Java/Spring Boot. In sealed-env enterprise mode, versions 0.1.0-alpha.1 through 0.1.0-alpha.3 embedded the operator's literal TOTP secret in the JWS payload of every minted unseal token. JWS payload is base64-encoded JSON, NOT encrypted. Any party who could observe a minted token (CI build logs, container env dumps, kubectl describe pod, Sentry/Rollbar stack traces, log aggregators) could decode the payload and extract the TOTP secret in plaintext. This vulnerability is fixed in 0.1.0-alpha.4.

Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.

dbcve analysis · high confidence

The sealed-env library versions 0.1.0-alpha.1 through 0.1.0-alpha.3 in enterprise mode embedded the operator's TOTP secret in plaintext within the base64-encoded (unencrypted) JWS payload of minted unseal tokens. Anyone with access to token outputs such as logs, CI outputs, container diagnostics, or error tracking systems could decode the payload and obtain the TOTP secret.

MitigationUpgrade to sealed-env version 0.1.0-alpha.4 or later, and rotate any TOTP secrets that may have been exposed through token observations.

Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.

CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.

From the vector
Attack vector
Network
Complexity
Low
Privileges
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.

dbcve checks

Work through these to decide whether this CVE applies to you.

  1. Identify sealed-env library version
    Check the installed version of the sealed-env package in your project (e.g., via package.json, requirements.txt, go.mod, or running npm list/pip show/equivalent). Compare it to the affected range: 0.1.0-alpha.1 through 0.1.0-alpha.3.
    Affected if The installed version falls within 0.1.0-alpha.1 to 0.1.0-alpha.3 inclusive.
  2. Confirm enterprise mode usage
    Inspect your sealed-env configuration or initialization code to determine whether enterprise mode is enabled. This is typically set via a configuration flag, environment variable, or code parameter at initialization.
    Affected if Enterprise mode is actively in use.
  3. Review token outputs for JWS payloads
    Search your log files, CI pipeline outputs, container diagnostics, error tracking systems, or any other systems where unseal token output may have been written. Look for base64-encoded strings that decode to JSON containing a 'totp_secret' or similar plaintext TOTP-related field within a JWS payload structure.
    Affected if Any token outputs exist that contain a plaintext TOTP secret in the decoded JWS payload.

You are affected if your sealed-env version is between 0.1.0-alpha.1 and 0.1.0-alpha.3 inclusive, enterprise mode is enabled, and any unseal token outputs (logs, CI, diagnostics) may have captured the JWS payload containing the plaintext TOTP secret.

Generated from the published advisory. Verify against your own configuration.

Check your environment

Paste your version and any relevant configuration and it will be compared against the affected criteria above. Do not include secrets or credentials.

AI-assisted, checked against the advisory. Informational, not a guarantee.

Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.

dbcve · scoped
Mitigation available No clean upgrade yet — mitigate in the meantime
Mitigation

Upgrade to sealed-env version 0.1.0-alpha.4 or later, and rotate any TOTP secrets that may have been exposed through token observations.

Recommended fix High confidence

0.1.0-alpha.4

  1. Identify the sealed-env package dependency in your project (check package.json, pom.xml, or build.gradle)
  2. Update sealed-env to version 0.1.0-alpha.4 or later
  3. For Node.js: Run 'npm update sealed-env' or manually update the version in package.json then run 'npm install'
  4. For Java/Spring Boot: Update the dependency version in your build file and rebuild
  5. After upgrading, verify that minted unseal tokens no longer contain the TOTP secret in the JWS payload
  6. Rotate any TOTP secrets that may have been exposed during the vulnerability window

Generated from the published advisory — verify against the referenced sources before acting.

Have this fixed Scoped from the published advisory
  • Consultation3.0 h
  • Implementation2.0 h
  • Testing4.0 h
  • Review / QA2.0 h
11.0 hours of engineering $1,920
Get help mitigating

An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $3,072.

Scan for this in your stack

Free · runs locally
dbcve dependency scanner

Check whether your project pulls in CVE-2026-45091 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.

References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.

Primary sources

Practitioner notes

Contributed

Peer-ranked notes from engineers who’ve handled CVE-2026-45091 in production — separate from our analysis above.

No notes yet

Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.

What this is

A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.

What belongs here
  • Verified mitigations, workarounds, and config changes
  • Version or environment caveats, and links to real fixes
  • No weaponised exploit code, or anything meant to cause harm
  • No spam, self-promotion, credentials, or personal data