CVE-2026-108584 PUBLISHED

FunnyWolf Viper config hard-coded credentials

Assigner: VulDB
Reserved: 10.10.2026 Published: 11.10.2026 Updated: 11.10.2026

A security flaw has been discovered in FunnyWolf Viper up to 3.1.11. The affected element is an unknown function of the file /root/viper/.git/config. Performing a manipulation results in hard-coded credentials. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
CVSS Score: 6.9

Product Status

Vendor FunnyWolf
Product Viper
Versions
  • Version 3.1.0 is affected
  • Version 3.1.1 is affected
  • Version 3.1.2 is affected
  • Version 3.1.3 is affected
  • Version 3.1.4 is affected
  • Version 3.1.5 is affected
  • Version 3.1.6 is affected
  • Version 3.1.7 is affected
  • Version 3.1.8 is affected
  • Version 3.1.9 is affected
  • Version 3.1.10 is affected
  • Version 3.1.11 is affected

Credits

  • Randark (VulDB User) reporter

References

Problem Types

  • Hard-coded Credentials CWE
  • Use of Hard-coded Password CWE