CVE-2026-61500 is an unauthenticated session-forgery vulnerability in Rejetto HFS 3.0.0 through 3.2.0. HFS generated its Koa session-cookie signing key with JavaScript Math.random() and exposed ...