Rare find

huntarr-security-review. Reproducible lab proving an unauthenticated authentication-bypass in Huntarr (v9.4.2): any endpoint is callable with zero credentials, leaking Huntarr's own passwords and the API keys of every *arr app it manages.

github.com/rfsbraz/huntarr-security-review

Vaya's read on this project

Problem, audience, market, and the verdict — sign in to see it.

Updates

No recent activity.