Security1 publisher2 min readPublished
Anthropic's Mythos model found a session-forgery path to RCE in Rejetto HFS 3.X
Horizon3 used Anthropic's Mythos model to find CVE-2026-61500, a chain that forges Rejetto HFS admin sessions and reaches remote code execution. The firm expects frontier models to make deeper, less reliable bug classes worth weaponizing at scale.
The Watch · Security desk

What happened
- HFS's administrative API lets custom endpoints run arbitrary JavaScript, so once an attacker holds an admin session the path runs to remote code execution on the host.
- The forged session works because HFS signs every cookie with a key seeded by one Math.random() value passed to the Koa keygrip framework it is built on.
- Mythos ran inside a harness that spawns specialized agents in parallel, and its cryptographic-weakness agent traced the cookie-signing chain across the codebase.
- Rejetto rewrote HFS from Delphi to TypeScript for its 3.X line, and that current version is what Horizon3 analyzed with a custom Mythos harness.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- capability An attacker no longer needs a cryptographer on staff: the model found the predictable-PRNG weakness and the way to leak the numbers needed to forge cookies.
- constraint Triage that ranks a complex, unreliable bug as low priority assumes attackers will not spend expert time weaponizing it; automated exploit reasoning weakens that assumption.
- exposure HFS installs that never set COOKIE_SIGN_KEYS fall back to the weak randomId(30) key, so those deployments are the ones an attacker can forge into.
- precedent Horizon3 says Mythos has already surfaced many critical vulnerabilities, so more complex chained disclosures from Project Glasswing are likely to follow.
Anthropic makes Mythos and started Project Glasswing to secure the world's most critical software [1]. Horizon3 joined in July 2026 and has run the model in its vulnerability research pipelines since [2]. It rates Mythos highest on computer-science and operating-system internals, mathematical distillations, and long-horizon tasks [4]. "Our use of Mythos thus far has exceeded what we thought was possible without significant harness engineering," the firm wrote [7].
From one finding, Horizon3 makes a wider claim about attacker economics. Its stated mission in the project was to find bugs likely to be exploited in the wild by threat actors at scale [3]. The usual target for mass exploitation is a simple authentication bypass that leads to built-in code execution; the firm expects more complex, less reliable bug classes to become viable because automation makes them cheap to run at scale [5]. It names automated ROP-chain construction across architectures and the weaponizing of memory-safety issues as the kind of work Mythos's results point to [6]. The reason the HFS key can be recovered at all is that V8's Math.random() uses the xorshift128+ generator, whose outputs are reversible; observe enough of them and the earlier numbers can be reconstructed [12].
The evidence here is one chain in one open-source file server [18], disclosed by the firm that built the pipeline. The finding is concrete [8]; the extrapolation to what threat actors will weaponize at scale is Horizon3's projection. HFS is not new to this: its 2.X line reached CISA's Known Exploited Vulnerabilities list for CVE-2024-23692, an unauthenticated template injection leading to code execution [9]. The writeup does not say whether Rejetto has patched the 3.X flaw, which versions are affected, or whether it has been exploited in the wild.
What to watch
- Whether Rejetto ships a patch for HFS 3.X and states which versions are affected.
- Whether the predictable-key session forgery shows up in the wild against internet-exposed HFS servers.
- Whether other Project Glasswing participants disclose similarly complex, chained flaws found with Mythos.