Action Center4
CriticalOpenNot run
northstar/core-platformapps/api/routes/admin/export.ts:14
Confidence
High
Owner
Unassigned
First observed
25 Aug 2026, 07:02 UTC
SLA remaining
1h 18m
Source run
RUN-8842
Fingerprint
fp:jwt.ts:38:91b2f1

Why this matters

Human-readable impact grounded in the verified target snapshot

A production signing key is committed to source and reachable by the authentication service.

An actor with repository read access could mint trusted session tokens. Rotation alone is insufficient until the committed key is removed from history and dependent credentials are invalidated.

Entry pointPOST /v1/session
Runtime pathauth-api → jwt.sign
EnvironmentProduction
ExploitabilityConfirmed

Evidence

Source provenance and integrity for every claim

1 verified artifact
No evidence artifacts are available for this fixture.