PACKAGIST · AUGUST 2026 · EARLY WARNING

Froxlor API Endpoints Disclose Sensitive Authentication Data

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
froxlor (packagist)
Affected versions
< 2.3.8
Patched version
Not yet available
GHSA-7788-GHFQ-C6MH

Froxlor API endpoints reportedly expose sensitive authentication material, including password hashes and TOTP 2FA seeds for customers, administrators, and FTP users. This can lead to account takeover and compromised 2FA.

What happened

Froxlor, a web hosting management software, is under investigation for a vulnerability in its API endpoints. The vulnerability, tracked as GHSA-7788-GHFQ-C6MH, reportedly allows the disclosure of sensitive authentication data, including password hashes and TOTP 2FA seeds. This exposure affects customers, administrators, and FTP users, potentially leading to account takeover and compromised 2FA. The vulnerability is present in versions of Froxlor prior to 2.3.8.

The issue was first flagged on August 18, 2026, and has been classified as high severity. The vulnerability has not been exploited in the wild, and there is no evidence of a supply-chain attack at this time. The primary source for this vulnerability is the GitHub Advisory Database, which provides detailed information on the affected components and recommended actions.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If froxlor is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if you are using a version of Froxlor prior to 2.3.8.

What should I do right now?

Upgrade to the latest version of Froxlor and review API responses for sensitive data exposure.

Is there an official fix available?

Yes, the official fix is to upgrade to Froxlor version 2.3.8 or later.

Where can I find more information about this vulnerability?

More information can be found in the GitHub Advisory Database under GHSA-7788-GHFQ-C6MH.

Sources

Join the 0Day waitlist →

← Back to all threats