Image
Dot. Manual
Image
Dot. Manual
Back to home

Dot.

Install Dot. AppDiagnostic Tool

Quote

Quote/0New
Pairing Quote/0How to TapShare with Family and FriendsHow to Charge
Content Mode
Loop ContentFixed Content
TimingNewApp Clip and Tap-to-InteractNew
Screen States and Troubleshooting
Update DeviceReset NetworkReset DeviceChangelogNew
Service and RepairCustomize Quote/0

Rand

Rand/0New
Getting StartedNew
FeaturesNew
Book of AnswersFortuneMBTI GuideWooden FishCoin FlipBluetooth RemoteNewPomodoroNewClockTimerNewDice RollNumber Under TenDisplay ModeNewNFC Cards
Wi-FiCustom WallpaperSettingsHow to Charge
Update DeviceReset DeviceChangelogNew
Service and RepairCustomize Rand/0

Read

Read PicoNew
Getting StartedNew
CrossMuxNewPico ReaderNewRickyOSNew
Demo SystemDIY Your System

Content & Services

Roadmap
Content Studio
Join Content StudioRSS
Shortcuts
Co CreateNew
SoftwareNew
Quote
Rand
ReadNew
HardwareNew
Quote
Rand
ReadNew
Open PlatformNew
What is an APIDot SkillNewGet API KeyGet Device Serial NumberGet Device ListGet Device StatusGet TimezonesNewDevice SettingsNewSwitch to Next ContentList Device ContentControl Text ContentNewControl Image ContentNewControl Canvas ContentNew

Explore More Possibilities

Request New ContentJoin Content StudioOur Repositories

Security

MSA-2025-08-001MSA-2025-09-001MSA-2025-09-002MSA-2025-10-001MSA-2025-10-002MSA-2025-10-003MSA-2026-04-001MSA-2026-10-001MSA-2026-10-002MSA-2026-10-003
Responsible Disclosure Policy

More

Service StatusService and RepairCustomize ProductsPrivacy PolicyUser AgreementContact UsAbout MindReset
SecuritySecurity Advisory
Image

MSA-2026-10-001

Missing server-side allowlist for API key prefixes

RSS

Release Date: Oct 08, 2026
Last Updated: Oct 08, 2026
Severity: Informational
Status: Fixed
CVSS 4.0 Score: 0.0 (AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N)


Overview

An authenticated user could change the prefix parameter when creating an API key and obtain a key with a prefix outside the supported Dot namespace. The server checked the prefix's format and length but did not restrict it to the prefixes supported by Dot.

This behavior has been addressed with a server-side allowlist and a consistent default prefix.

Impact Scope

ItemDetails
Affected ProductDot Server-side API
Affected VersionAPI key creation endpoint before the server-side fix
Fixed VersionServer-side fix
Affected Component/api/authV2/api-key/create
Attack VectorNetwork
Required PrivilegeLow (authenticated user creating keys for their account)

Technical Description

The creation endpoint accepted a client-provided prefix and included it in the generated key. Validation allowed prefixes that met the underlying API key plugin's character and length requirements, even when they were outside Dot's supported set.

The prefix did not determine the key's owner or grant additional permissions. API key authentication verified the complete key and resolved its stored owner; access to protected resources remained subject to authorization checks.

Potential Consequences

  • Keys could be created with unsupported names, causing inconsistent key identification or rejection by integrations that expect Dot's supported prefixes.

Remediation

  • Strengthened server-side validation of API key prefixes.
  • Added clear errors for unsupported values.

Impact Assessment

We classify this issue as Informational. The assessed impact is limited to key naming and validation. Changing a prefix does not confer another user's identity or additional access rights, and no confidentiality, integrity, or availability impact has been established. The CVSS 4.0 base score is 0.0.

User Action

No client update is required. Integrations creating API keys should use a supported prefix or omit the parameter to use dot_.

Acknowledgements

We thank Shuvo Kumar Saha (Syper-shuvo) for reporting this issue through responsible disclosure and helping us improve API key validation.


Disclaimer: This advisory reflects information available at publication and will be updated if material changes occur.
Document ID: MSA-2026-10-001
Classification: Public
Issued by: MindReset Security Team

Did this solve your problem?

Join our community

MSA-2026-04-001

Hardcoded bearer token in OTA firmware enabling arbitrary firmware record tampering

MSA-2026-10-002

Insufficient verification email throttling allowed repeated sends to the same recipient

Contents

OverviewImpact ScopeTechnical DescriptionPotential ConsequencesRemediationImpact AssessmentUser ActionAcknowledgements