Image
Dot. Manual
Image
Dot. Manual
Back to home

Dot.

Install Dot. AppDiagnostic Tool

Quote

Quote/0New
Pairing Quote/0How to TapShare with Family and FriendsHow to Charge
Content Mode
Loop ContentFixed Content
TimingNewApp Clip and Tap-to-InteractNew
Screen States and Troubleshooting
Update DeviceReset NetworkReset DeviceChangelogNew
Service and RepairCustomize Quote/0

Rand

Rand/0New
Getting StartedNew
FeaturesNew
Book of AnswersFortuneMBTI GuideWooden FishCoin FlipBluetooth RemoteNewPomodoroNewClockTimerNewDice RollNumber Under TenDisplay ModeNewNFC Cards
Wi-FiCustom WallpaperSettingsHow to Charge
Update DeviceReset DeviceChangelogNew
Service and RepairCustomize Rand/0

Read

Read PicoNew
Getting StartedNew
CrossMuxNewPico ReaderNewRickyOSNew
Demo SystemDIY Your System

Content & Services

Roadmap
Content Studio
Join Content StudioRSS
Shortcuts
Co CreateNew
SoftwareNew
Quote
Rand
ReadNew
HardwareNew
Quote
Rand
ReadNew
Open PlatformNew
What is an APIDot SkillNewGet API KeyGet Device Serial NumberGet Device ListGet Device StatusGet TimezonesNewDevice SettingsNewSwitch to Next ContentList Device ContentControl Text ContentNewControl Image ContentNewControl Canvas ContentNew

Explore More Possibilities

Request New ContentJoin Content StudioOur Repositories

Security

MSA-2025-08-001MSA-2025-09-001MSA-2025-09-002MSA-2025-10-001MSA-2025-10-002MSA-2025-10-003MSA-2026-04-001MSA-2026-10-001MSA-2026-10-002MSA-2026-10-003
Responsible Disclosure Policy

More

Service StatusService and RepairCustomize ProductsPrivacy PolicyUser AgreementContact UsAbout MindReset
SecuritySecurity Advisory
Image

MSA-2026-10-003

Concurrent API key creation could bypass the ten-key account limit

RSS

Release Date: Oct 08, 2026
Last Updated: Oct 08, 2026
Severity: Low
Status: Fixed
CVSS 4.0 Score: 2.3 (AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N)


Overview

An authenticated user could submit concurrent API key creation requests that passed the account's ten-key limit check before any of the requests completed its database insert. This race condition allowed additional keys to be stored for that user's account.

The account limit is now enforced for concurrent requests as well as individual requests.

Impact Scope

ItemDetails
Affected ProductDot Server-side API
Affected VersionAPI key creation endpoint before the server-side fix
Fixed VersionServer-side fix
Affected Component/api/authV2/api-key/create
Attack VectorNetwork
Required PrivilegeLow (authenticated user creating keys for their account)

Technical Description

The server first counted the user's existing keys and then performed a separate insert. Several concurrent requests could observe a count below ten and each proceed to create a key. Concurrent deletion and creation could also change the count between the check and the insert.

The key list interface displayed a limited number of entries, but that display limit did not constrain the records stored in the database.

The additional keys remained associated with the authenticated user's account and retained the normal authorization checks. The affected resources were API keys; the endpoint did not create relay proxies.

Potential Consequences

  • Creation of more API key records than the account policy allowed.
  • Increased credential storage and management overhead for the affected account.

Remediation

  • Strengthened account-level quota enforcement during concurrent requests.
  • Improved handling of key creation and deletion to keep limits consistent.

Impact Assessment

We classify this issue as Low, with a CVSS 4.0 base score of 2.3. Exploitation requires an authenticated account (PR:L) and winning a timing race (AT:P). The confirmed consequence is a limited integrity impact on the account's key-count policy (VI:L). Additional keys do not grant access to another account or broader permissions, and service-wide availability loss has not been established.

User Action

No client update or key rotation is required to address this issue. If an account already has ten or more keys, delete unused keys before creating another.

Acknowledgements

We thank Shuvo Kumar Saha (Syper-shuvo) for responsibly reporting the API key quota race condition and providing reproduction details.


Disclaimer: This advisory reflects information available at publication and will be updated if material changes occur.
Document ID: MSA-2026-10-003
Classification: Public
Issued by: MindReset Security Team

Did this solve your problem?

Join our community

MSA-2026-10-002

Insufficient verification email throttling allowed repeated sends to the same recipient

Responsible Disclosure Policy

Our responsible disclosure policy encourages security researchers and users to report security vulnerabilities.

Contents

OverviewImpact ScopeTechnical DescriptionPotential ConsequencesRemediationImpact AssessmentUser ActionAcknowledgements