Skip to content

Security report: potential findings in full-stack-fastapi-template #2387

Description

@leeyu44

Hello maintainers,

I am opening this issue to establish vendor contact for a security review of full-stack-fastapi-template. The local report identifies the following potential security findings:

  • . Summary
  • . FINDING 1: Default SECRET_KEY Enables Full JWT Forgery
  • Affected Code
  • Steps to Reproduce
  • Verified Results
  • .5 Impact
  • Recommended Fix
  • . FINDING 2: No Rate Limiting on Authentication Endpoints

Affected version / commit tested: reported tested version; confirm with vendor

I am intentionally keeping exploit steps, payloads, and sensitive values out of this public issue. If you prefer a private channel or a GitHub Security Advisory, please point me to it and I can provide full reproduction notes there.

Reporter credit: logicfuzz

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions