CVE-2026-45091, sealed-env: TOTP secret embedded in unseal token payload (enterprise mode)
Source: Endorlabs
Published:
<p>In sealed-env enterprise mode, versions 0.1.0-alpha.1 through 0.1.0-alpha.3 embedded the operator's literal TOTP secret in the JWS payload of every minted unseal token. JWS payload is base64-encoded JSON, NOT encrypted. Any party who could observe a minted token (CI build logs, container env dump