Skip to content
Brief Security & Trust ·

Researcher reports 15 flaws in Internxt's encrypted cloud storage

A researcher says a link can run code on Internxt's desktop app, and that its key design lets the firm read user data.

In brief
  • A researcher reported 15 findings in Internxt. A link can run code in desktop versions up to 2.6.12, and a crafted login link in any browser can leak keys.
  • He says the key design lets Internxt read or change user data and cannot be patched quickly. Version 2.7 is due next week.

A security researcher reported 15 findings in Internxt, an encrypted storage firm, in a 3 October post on schaerli.org. In desktop versions up to 2.6.12, a malicious link can run code, because the app passes internxt:// links to the operating system unchecked. A crafted login link opened in any browser can also leak a user's encryption key and login token. No desktop app is needed.

Every file key comes from one 24-word secret, the mnemonic, that never changes. The researcher says sharing a folder hands that secret over, and Internxt's server can intercept it, so the firm could read or change data. Three MD5 rounds turn the password into the key protecting it. On his graphics card, a billion guesses took about four seconds. Internxt told him version 2.7, with the code fix, is due next week. His web fix is merged; the post does not say if it is live. He says the key design cannot be patched quickly, and it is not tied to any version.

"Zero-knowledge" and "audited" are claims, not proof of key design. Internxt says its 2025 audit found no severe flaws, but the report is unpublished. Buyers can ask: is the full report available, can the vendor read keys, are update signatures checked? The post says Internxt turns that check off.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: schaerli.org.