Skip to content

Security report: potential findings in full-stack-fastapi-template #2387

Description

@leeyu44

Hello maintainers,

I am opening this issue to establish vendor contact for a security review of full-stack-fastapi-template. The local report identifies the following potential security findings:

  • . Summary
  • . FINDING 1: Default SECRET_KEY Enables Full JWT Forgery
  • Affected Code
  • Steps to Reproduce
  • Verified Results
  • .5 Impact
  • Recommended Fix
  • . FINDING 2: No Rate Limiting on Authentication Endpoints

Affected version / commit tested: reported tested version; confirm with vendor

I am intentionally keeping exploit steps, payloads, and sensitive values out of this public issue. If you prefer a private channel or a GitHub Security Advisory, please point me to it and I can provide full reproduction notes there.

Reporter credit: logicfuzz

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions