CVE-2023-31579: Tangyh Lamp-Cloud

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Dromara Lamp-Cloud before v3.8.1 was discovered to use a hardcoded cryptographic key when creating and verifying a Json Web Token. This vulnerability allows attackers to authenticate to the application via a crafted JWT token.

Affected products

  • Tangyh Lamp-Cloud: before 3.8.1 (fixed in 3.8.1)

Published 2023-11-02. Last modified 2026-06-17.