Froxlor API Endpoints Disclose Sensitive Authentication Data
- Severity
- HIGH
- Affected component
- froxlor (packagist)
- Affected versions
- < 2.3.8
- Patched version
- Not yet available
Froxlor API endpoints reportedly expose sensitive authentication material, including password hashes and TOTP 2FA seeds for customers, administrators, and FTP users. This can lead to account takeover and compromised 2FA.
What happened
Froxlor, a web hosting management software, is under investigation for a vulnerability in its API endpoints. The vulnerability, tracked as GHSA-7788-GHFQ-C6MH, reportedly allows the disclosure of sensitive authentication data, including password hashes and TOTP 2FA seeds. This exposure affects customers, administrators, and FTP users, potentially leading to account takeover and compromised 2FA. The vulnerability is present in versions of Froxlor prior to 2.3.8.
The issue was first flagged on August 18, 2026, and has been classified as high severity. The vulnerability has not been exploited in the wild, and there is no evidence of a supply-chain attack at this time. The primary source for this vulnerability is the GitHub Advisory Database, which provides detailed information on the affected components and recommended actions.
What to do about it
- Upgrade to the latest version of Froxlor, which is 2.3.8 or later.
- Review API responses for any exposure of sensitive data.
- Monitor the primary sources for updates on the vulnerability and any additional patches that may be released.
How 0Day would have caught this
froxlor is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using a version of Froxlor prior to 2.3.8.
What should I do right now?
Upgrade to the latest version of Froxlor and review API responses for sensitive data exposure.
Is there an official fix available?
Yes, the official fix is to upgrade to Froxlor version 2.3.8 or later.
Where can I find more information about this vulnerability?
More information can be found in the GitHub Advisory Database under GHSA-7788-GHFQ-C6MH.