CRITICAL GitHub
CVE-2026-55445
Qinglong has an incomplete fix for CVE-2026-3965: Improper Authentication
### Summary
The init guard middleware in Qinglong only checks `/api/user/init` paths but not `/open/user/init`, which is whitelisted from JWT authentication and rewritten to `/api/user/init` after the guard has already passed, allowing unauthenticated admin credential reset on initialized instances.
### Affected Package
- **Ecosystem:** npm
- **Package:** whyour/qinglong
- **Affected versions:** < 6bec52dca158
- **Patched versions:** >= 6bec52dca158
### Severity
Medium
### CWE
CWE-287 — I
Affected Products
- npm/@whyour/qinglong < 2.20.1
References
- https://github.com/advisories/GHSA-v667-gc2r-2xm7
- https://github.com/whyour/qinglong/security/advisories/GHSA-v667-gc2r-2xm7
- https://nvd.nist.gov/vuln/detail/CVE-2026-55445
- https://github.com/whyour/qinglong/pull/2941
This critical severity vulnerability was published on 2026-08-20 via GitHub. Affected: npm/@whyour/qinglong < 2.20.1.
vulnfeed aggregates 11796 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.