Hello maintainers,
I am opening this issue to establish vendor contact for a security review of full-stack-fastapi-template. The local report identifies the following potential security findings:
- . Summary
- . FINDING 1: Default
SECRET_KEY Enables Full JWT Forgery
- Affected Code
- Steps to Reproduce
- Verified Results
- .5 Impact
- Recommended Fix
- . FINDING 2: No Rate Limiting on Authentication Endpoints
Affected version / commit tested: reported tested version; confirm with vendor
I am intentionally keeping exploit steps, payloads, and sensitive values out of this public issue. If you prefer a private channel or a GitHub Security Advisory, please point me to it and I can provide full reproduction notes there.
Reporter credit: logicfuzz
Hello maintainers,
I am opening this issue to establish vendor contact for a security review of full-stack-fastapi-template. The local report identifies the following potential security findings:
SECRET_KEYEnables Full JWT ForgeryAffected version / commit tested: reported tested version; confirm with vendor
I am intentionally keeping exploit steps, payloads, and sensitive values out of this public issue. If you prefer a private channel or a GitHub Security Advisory, please point me to it and I can provide full reproduction notes there.
Reporter credit: logicfuzz