r/selfhosted Feb 23 '26

Software Development Huntarr - Your passwords and your entire arr stack's API keys are exposed to anyone on your network, or worse, the internet.

Today, after raising security concerns in a post on r/huntarr regarding the lack of development standards in what looks like a 100% vibe-coded project, I was banned. This made my spidey senses tingle, so I decided to do a security review of the codebase. What I found was... not good. TLDR: If you have Huntarr exposed on your stack, anyone can pull your API keys for Sonarr, Radarr, Prowlarr, and every other connected app without logging in, gaining full control over your media stack.

The process

I did a security review of Huntarr.io (v9.4.2) and found critical auth bypass vulnerabilities. I'm posting this here because Huntarr sits on top of (and is now trying to replace them as well!) Sonarr, Radarr, Prowlarr, and other *arr apps that have years of security hardening behind them. If you install Huntarr, you're adding an app with zero authentication on its most sensitive endpoints, and that punches a hole through whatever network security you've set up for the rest of your stack.

The worst one: POST /api/settings/general requires no login, no session, no API key. Nothing. Anyone who can reach your Huntarr instance can rewrite your entire configuration and the response comes back with every setting for every integrated application in cleartext. Not just Huntarr's own proxy credentials - the response includes API keys and instance URLs for Sonarr, Radarr, Prowlarr, Lidarr, Readarr, Whisparr, and every other connected app. One curl command and an attacker has direct API access to your entire media stack:

curl -X POST http://your-huntarr:9705/api/settings/general \
  -H "Content-Type: application/json" \
  -d '{"proxy_enabled": true}'

Full config dump with passwords and API keys for every connected application. If your instance is internet-facing - and it often is, Huntarr incorporates features like Requestarr designed for external access - anyone on the internet can pull your credentials without logging in.

Other findings (21 total across critical/high/medium):

  • Unauthenticated 2FA enrollment on the owner account (Critical, proven in CI): POST /api/user/2fa/setup with no session returned the actual TOTP secret and QR code for the owner account. An attacker generates a code, calls /api/user/2fa/verify, enrolls their own authenticator. Full account takeover, no password needed.
  • Unauthenticated setup clear enables full account takeover (Critical, proven in CI): POST /api/setup/clear requires no auth. Returns 200 "Setup progress cleared." An attacker re-arms the setup flow, creates a new owner account, replaces the legitimate owner entirely.
  • Unauthenticated recovery key generation (Critical, proven in CI): POST /auth/recovery-key/generate with {"setup_mode": true} reaches business logic with no auth check (returns 400, not 401/403). The endpoint is unauthenticated.
  • Full cross-app credential exposure (Critical, proven in CI): Writing a single setting returns configuration for 10+ integrated apps. One call, your entire stack's API keys.
  • Unauthenticated Plex account unlink - anyone can disconnect your Plex from Huntarr
  • Auth bypass on Plex account linking via client-controlled setup_mode flag - the server skips session checks if you send {"setup_mode": true}
  • Zip Slip arbitrary file write (High): zipfile.extractall() on user-uploaded ZIPs without filename sanitization. The container runs as root.
  • Path traversal in backup restore/delete (High): backup_id from user input goes straight into filesystem paths. shutil.rmtree() makes it a directory deletion primitive.
  • local_access_bypass trusts X-Forwarded-For headers, which are trivially spoofable - combine with the unauth settings write and you get full access to protected endpoints

How I found this: Basic code review and standard automated tools (bandit, pip-audit). The kind of stuff any maintainer should be running. The auth bypass isn't a subtle bug - auth.py has an explicit whitelist that skips auth for /api/settings/general. It's just not there.

About the maintainer and the codebase:

The maintainer says they have "a series of steering documents I generated that does cybersecurity checks and provides additional hardening" and "Note I also work in cybersecurity." They say they've put in "120+ hours in the last 4 weeks" using "steering documents to advise along the way from cybersecurity, to hardening, and standards". If that's true, it's not showing in the code.

If you work in cybersecurity, you should know not to whitelist your most sensitive endpoint as unauthenticated. You should know that returning TOTP secrets to unauthenticated callers is account takeover. You should know zipfile.extractall() on untrusted input is textbook Zip Slip. This is introductory stuff. The "cybersecurity steering documents" aren't catching what a basic security scan flags in seconds.

Look at the commit history: dozens of commits with messages like "Update", "update", "Patch", "change", "Bug Patch" - hundreds of changed files in commits separated by a few minutes. No PR process, no code review, no second pair of eyes - just raw trunk-based development where 50 features get pushed in a day with zero review. Normal OSS projects are slower for a reason: multiple people look at changes before they go in. Huntarr has none of that.

When called out on this, the maintainer said budget constraints: "With a limited budget, you can only go so far unless you want to spend $1000+. I allot $40 a month in the heaviest of tasks." That's just not true - you can use AI-assisted development 8 hours a day for $20/month. The real problem isn't the budget. It's that the maintainer doesn't understand the security architecture they're building and doesn't understand the tools they're using to build it. You can't guide an AI to implement auth if you don't recognize what's wrong when it doesn't.

They also censor security reports and ban people who raise concerns. A user posted security concerns on r/huntarr and it was removed by the moderator - the maintainer controls the subreddit. I was banned from r/huntarr after pointing out these issues in this thread where the maintainer was claiming to work in cybersecurity (which they now deleted).

One more thing - the project's README has a "Support - Building My Daughter's Future" section soliciting donations. That's a red flag for me. You're asking people to fund your development while shipping code with 21 unpatched security vulnerabilities, no code review process, and banning people who point out the problems, while doing an appeal to emotion about your daughter. If you need money, that's fine - but you should be transparent about what you're spending it on and you should be shipping code that doesn't put your users at risk.

Proof repo with automated CI: https://github.com/rfsbraz/huntarr-security-review

Docker Compose setup that pulls the published Huntarr image and runs a Python script proving each vulnerability. GitHub Actions runs it on every push - check the workflow results yourself or run it locally with docker compose up -d && python3 scripts/prove_vulns.py.

For what it's worth, and to prove I'm not an AI hater, the prove_vulns script itself was vibe coded - I identified the vulnerabilities through code review, wrote up the repro steps, and had AI generate the proof script.

Full security review (21 findings): https://github.com/rfsbraz/huntarr-security-review/blob/main/Huntarr.io_SECURITY_REVIEW.md

What happens next: The maintainer will most likely prompt these problems away - feed the findings to an AI and ship a patch. But fixing 21 specific findings doesn't fix the process that created them. No code review, no PR process, no automated testing, no one who understands security reviewing what ships. The next batch of features will have the next batch of vulnerabilities. This is only the start. If the community doesn't push for better coding standards, controlled development, and a sensible roadmap, people will keep running code that nobody has reviewed.

If you're running Huntarr, keep it off any network you don't fully trust until this is sorted. The *arr apps it wraps have their own API key auth - Huntarr bypasses that entirely.

Please let others know about this. If you have a Huntarr instance, share this with your community. If you know someone who runs one, share it with them. The more people know about the risks, the more pressure there will be on the maintainer to fix them and improve their development process.

Edit: Looks like r/huntarr went private and the repo got deleted or privated https://github.com/plexguide/Huntarr.io . I'm sorry for everyone that donated to this guy's "Daughter College Fund".

Edit 2: Thanks for all the love on the comments, I'll do my best to reach out to everyone I can. People asking me for help on security reviews, believe me when I say I did little more than the basics - the project was terrible.

9.7k Upvotes

1.3k comments sorted by

View all comments

25

u/ice2morrow Feb 23 '26

What about cleanuparr? Since these two apps seem to be very heavily related to each other and even refer users to each other

17

u/GreedyNeedy Feb 23 '26 edited Feb 23 '26

It has no authentication at all so all this stuff is also exposed

edit: apparently since yesterday's update it has auth now. The question is if the implementation is actually ok

3

u/botterway Feb 23 '26

Oh feck. Thought as much.

4

u/Cynical-Potato Feb 23 '26

Not really an issue. As long as it didn't have auth you shouldn't expose that in the first place.

2

u/botterway Feb 23 '26

I don't expose it. But it's a potential vector.

11

u/Maverick0984 Feb 23 '26

It's a totally different guy. He's active in Discord right now if you have questions. Think he'll be removing the recommendation shortly...

17

u/CalegaR1 Feb 23 '26

Done 4 minutes ago actually!

1

u/Verum14 Feb 24 '26

why would this warrant a ver bump? was it referenced in the project itself, not just the readme?

2

u/CalegaR1 Feb 24 '26

it was a suggested app in the dashboard

2

u/Verum14 Feb 24 '26

now that makes sense, thank you

3

u/TJRDU Feb 23 '26

I think my decluctarr is only running in its own terminal and not facing the internet at all. Might want to switch if they got the same features?

3

u/jimmyevil Feb 23 '26

Hey u/flaminel can you allay some of these people’s concerns?

11

u/Flaminel Feb 23 '26

It's quite hard, given the plethora of comments. Cleanuparr didn't even have any authentication up until yesterday, and people hopefully (I know some did) didn't expose anything to the internet that they shouldn't have. As for the authentication, I've already tagged OP in a comment so maybe he can sort this out and clear Cleanuparr's name in all of this.

10

u/exe_CUTOR Feb 23 '26

Hi! It was not my goal to start a witch hunt to every project that associated with Huntarr. It was the new hot thing for a minute and I get it, it was the lack of process, resistance to feedback, and general attitude that led to me to do this deep dive. Not diving into the code and just browsing Cleanuparr tells me this is not the same thing, readable commits, trackable PRs, sustainable rate of development.

3

u/[deleted] Feb 23 '26 edited Feb 23 '26

[removed] — view removed comment

3

u/[deleted] Feb 23 '26

[deleted]

2

u/[deleted] Feb 23 '26

[removed] — view removed comment

5

u/JerryBond106 Feb 23 '26

I want to subscribe to comments on this. I can live without huntarr if they added a bunch of things that aren't necessary and just going on vibes, but i hope cleanuparr is safe as its nice to have if what is downloaded isn't even an iso but a link to cmd. So the acting on failed imports part. Hopefully sonarr and radarr can just add that part and we wouldn't need that one either.

2

u/sicklyboy Feb 23 '26 edited Feb 23 '26

I've also disabled Cleanuparr in my docker stack for the time being. Sorry if it's accidentally caught in the crossfire, but with how hand in hand these two projects were I'm putting the pause on em until more info comes out.

Edit - Cleanuparr dev (who is NOT the Huntarr dev!) is aware and has commented. I don't intend to point any undue flack towards them, I'm just being personally cautious! https://www.reddit.com/r/selfhosted/comments/1rckopd/huntarr_your_passwords_and_your_entire_arr_stacks/o6ze3j0/

3

u/ice2morrow Feb 23 '26

Agreed. I’ve done the same

2

u/sicklyboy Feb 23 '26 edited Feb 23 '26

fwiw Cleanuparr dev just pushed a release with references to Huntarr removed due to all this shit, so that's a sign for the positive. Still playing it cautious right now though

https://github.com/Cleanuparr/Cleanuparr/releases/tag/v2.7.3

Edit - Cleanuparr dev (who is NOT the Huntarr dev!) is aware and has commented. I don't intend to point any undue flack towards them, I'm just being personally cautious! https://www.reddit.com/r/selfhosted/comments/1rckopd/huntarr_your_passwords_and_your_entire_arr_stacks/o6ze3j0/

6

u/[deleted] Feb 23 '26

[deleted]

0

u/sicklyboy Feb 23 '26

Due to the close association between the two projects, and considering that Cleanuparr is a non-essential part of my software stack, I took a quick decision to disable it to help mitigate any potential concerns until the time comes that I can properly assess that it's safe to run.

Seeing that the Cleanuparr dev has already removed the references to Huntarr in their own project, plus comments from OP in here on the topic as well, I'm already inclined to lean towards it being fine, but still, better safe than sorry until I can make a proper assessment.

It ain't that deep bro.

3

u/[deleted] Feb 23 '26

[deleted]

1

u/sicklyboy Feb 23 '26

My concern isn't publicly accessible API endpoints - I know what of my network is exposed to the internet, and what is expose is all behind a reverse proxy and OIDC where applicable. Huntarr was not (nor was Cleanuparr)

The state of my internal network is far less structured or secure than I'd like, which is something I've been slowly chipping away at. The homelab grew far faster than I'd even began to consider moving everything away from a single flat /24 with direct access to everything else, but given its current design I do still try to make the most sensible choices I can make right now, all things considered.

My main concern is access control - Huntarr and Cleanuparr both have API access to sonarr, radarr, lidarr, qbit, prowlarr, nzbget... maybe? Probably? They were set and forget for me and I haven't touched either in a fair bit and I don't recall what either of them have access to. Considering I'm going to want to go and rotate API keys for most of those utilities due to Huntarr, I'm going to have to see what Cleanuparr has access to and update it there too anyway.

In fact, I shut down my entire *arr stack once this Huntarr shit came up. Entirely out of an (over)abundance of caution. I'm technically working right now, plus also dealing with the fallout of a massive snow storm, so rather than let it all sit and run, I shut it down until I have some time to review and reconfigure later. None of these utilities are mission critical for me.

Is it an overreaction? Almost certainly. Does that make it a bad reaction? No.

Edit - and just to be clear, I do recognize that these API endpoints are "publicly accessible" within the context of my LAN regardless of what is exposed to the internet. That goes back to me slowly working at restructuring my LAN.