Cryptomator Hub-Based Unlock Flow Insecure Endpoint Vulnerability

Vulnerability

A vulnerability exists in Cryptomator's Hub-based unlock flow prior to version 1.19.1, allowing vault configurations to direct OAuth and key-loading traffic over unencrypted HTTP or other insecure endpoints. This oversight enables active network attackers to intercept or manipulate this traffic. Even with encrypted vault keys, bearer tokens and endpoint trust decisions remain vulnerable to interception and downgrading.

Impact

Exploitation of this vulnerability could lead to interception of OAuth bearer tokens and manipulation of endpoint responses, device registration, and key delivery traffic. Additionally, a malicious vault configuration could redirect the desktop client to attacker-controlled endpoints without any trust verification or transport security enforcement.

Reproduction

To reproduce this vulnerability, create or modify a Hub-backed vault configuration to use 'hub+http' or direct its metadata endpoints to non-HTTPS URLs. When the vault is opened in Cryptomator, the application will perform OAuth and API requests over the insecure transport, exposing bearer tokens and other sensitive data to interception or tampering.

Remediation

Users should update to Cryptomator version 1.19.1 or later, which removes support for 'hub+http' in production builds and enforces HTTPS for all Hub endpoint values.

Added: Mar 20, 2026, 7:28 PM
Updated: Mar 20, 2026, 7:28 PM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
3.5
exploitability
5.4
remediation
7.7
relevance
4.2
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.