Alby Hub old versions have critical vulnerability; publicly exposed management API could lead to fund transfer
2026-09-09 08:05
Odaily Planet Daily News: Bitcoin News posted on X platform stating that Alby has confirmed a critical vulnerability in Alby Hub v1.7.0 to v1.18.5. If the management API is exposed to the public network, attackers could gain unauthorized access and transfer funds. Currently, one user is known to be affected, and Alby Hub v1.19.0 and later versions are not affected. Alby recommends affected users restrict public network access to the management interface, update immediately to v1.24.0, and change the unlock password after updating. Multiple issues reported by Bitcoin Team Red, Project Loupe, and other researchers have also been fixed in the latest version.
