Alby confirmed a critical vulnerability in Alby Hub versions 1.7.0 through 1.18.5 that could allow unauthorized access and fund transfers if the management API is exposed to the public internet. According to Odaily, one user has been affected, while Alby Hub version 1.19.0 and later are not impacted.
Alby advised affected users to restrict public access to the management interface, update immediately to version 1.24.0, and change the unlock password after updating. The company also said multiple issues reported by Bitcoin Team Red, Project Loupe, and other researchers have been fixed in the latest version.