Impact
A vulnerability exists in the Planet9 desktop application where a hardcoded read‑only API key is embedded in the binary. This key grants access to internal repositories, enabling an attacker to extract administrative keys and secrets. With those credentials, the attacker can obtain administrative rights to the repository infrastructure, potentially modifying software source code and compromising the integrity of the codebase.
Affected Systems
All Acer Planet9 desktop application clients prior to version v2.8.128 are affected. The vendor provides a fix in version v2.8.128, which removes the hardcoded credential and automatically updates clients when available.
Risk and Exploitability
The CVSS score of 6.6 indicates moderate severity; EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers would need local or privileged access to the target machine to extract the hardcoded key, or that the attack could target a system already running the application. The description does not mention a remote attack path, so indirect exploitation appears unlikely without additional weaknesses.
OpenCVE Enrichment