
🚨Critical - sealed-env TOTP Secret Exposure in Unseal Token (CVE-2026-45091) In sealed-env enterprise mode, versions prior to 0.1.0-alpha.4 embed the operator's literal TOTP secret directly in the base64-encoded JWS payload of minted unseal tokens. Any observer who can access a token (e.g., CI logs, container dumps, or error trackers) can extract the secret in plaintext. This breaks the second-factor protection: an attacker with the master key and one leaked token can mint unlimited new unseal tokens indefinitely. 👉Affected: sealed-env < 0.1.0-alpha.4 (Maven + npm)
Post summary
The post announces a new critical vulnerability (CVE-2026-45091) affecting sealed‑env prior to 0.1.0‑alpha.4, detailing how the TOTP secret is exposed in unseal tokens without providing PoC or exploit code.
