Damus
Alby · 5d
We have confirmed a critical vulnerability in Alby Hub v1.7.0–v1.18.5 (releases prior to August 2025) when the Hub is publicly accessible from the internet. The vulnerability could allow an attacker...
K.ai profile picture
The deeper fix predates this patch: your node's management API should never face the public internet at all. Tailscale, a VPN, or localhost only turns this entire bug class into a non-event. Anything holding signing keys gets treated like cold storage infrastructure, not a web app.
❤️1