Horizon3 Says Anthropic’s Mythos Turned a File-Server Flaw Into a Working Exploit
The model reportedly connected two weaknesses to forge administrator access. Researchers say it pursued cryptographic work they would previously have abandoned.
Loading page…
The model reportedly connected two weaknesses to forge administrator access. Researchers say it pursued cryptographic work they would previously have abandoned.
Listen to this story
Horizon3.ai reports that Mythos turned a vulnerability in Rejetto HFS 3.x into server-side command execution by recovering the session-signing key and forging an administrator cookie. The exploit depended on a login-enabled username and exposed Math.random() outputs; Horizon3 says Mythos connected the leak to the key and used a Z3 solver, without follow-on prompting. The case suggests advanced models may make complex bugs cheaper to exploit, but broader exploitation at scale is Horizon3’s forecast, not an outcome demonstrated here. No fixed release or patch timeline is identified for HFS operators.
Horizon3 disclosed the flaw as CVE-2026-61500 on September 30, 2026.
The endpoint exposed readable values in signed, unencrypted cookies; exploiting the path required a valid username enabled for login.
Horizon3 says it used specialized research agents and has had Mythos in its pipeline since joining Anthropic’s Project Glasswing in July 2026.
A weakness security researchers might once have left unexplored became a working server takeover, according to Horizon3.ai. In its September 30, 2026 disclosure, the company said Anthropic’s Mythos connected flaws in Rejetto HTTP File Server’s login system, forged administrator access and demonstrated remote command execution. The finding, CVE-2026-61500, affects HFS 3.x, an open-source tool for hosting and sharing files.
HFS uses a signing key to prove that a session cookie is genuine. In the configuration Horizon3 examined, that key came from Math.random(), a JavaScript function whose outputs are not designed to protect secrets. Its underlying generator is reversible: enough observed outputs can reveal its internal state and earlier values.
That weakness alone was not the full attack. A separate login-related endpoint exposed values from the same generator without requiring a password. Those values appeared inside cookies that were signed but not encrypted, so a client could read them. Access required a valid username enabled for login.
Horizon3 says Mythos recognized the connection: the exposed numbers could help reconstruct the secret used to authenticate sessions. Rather than treating the random-number function as an isolated coding mistake, it identified a route from leaked values to administrator access.
The company ran Mythos inside a custom research system that assigned specialized agents to different vulnerability classes. A cryptography-focused agent raised the finding; a second agent checked the code and judged it valid. Horizon3 says it has used Mythos in its research pipeline since joining Anthropic’s Project Glasswing in July 2026.
Mythos then implemented a Z3 solver—a tool that finds solutions satisfying a set of mathematical conditions—to recover the generator’s state. Horizon3 says it reconstructed the signing key and produced a forged administrator cookie. HFS’s administrative interface allows custom endpoints to execute JavaScript, providing the final path to running a command on the server.
It did not require follow-on prompting to find the disparate PRNG leak that made this theoretical issue a demonstrable one.
Zach Hanley, Horizon3.ai
The researchers’ comparison is with their own previous approach, not a competing model. They say they had often abandoned cryptographic findings because they lacked deep mathematical expertise or could not justify the time needed to build an exploit. For this flaw, their initial approach would have considered brute force rather than the solver-based solution.
Horizon3 argues that stronger models could make more complex vulnerabilities economical to exploit at scale. That is its forecast, not a demonstrated outcome of this case. It also says research-system design still matters, especially for heavily reviewed software, and leaves researchers responsible for deciding where specialized investigation is worth the effort.
For HFS operators, the disclosure leaves a practical gap: it does not identify a fixed release or provide a patch timeline.
Loading discussion...
Join the conversation
Explain which side you think benefits more, and why.
Be the first to share a perspective or an experience.
Reader comments
Newest comments first. Replies stay oldest first.