VDB
Sign up
HIGH

GHSA-8v5f-hp78-jgxq

Signature Verification Bypass in jwt-simple

Quick fix

GHSA-8v5f-hp78-jgxq — jwt-simple: upgrade to the fixed version with the command below.

npm install jwt-simple@0.5.3

Details

Versions of `jwt-simple` prior to 0.5.3 are vulnerable to Signature Verification Bypass. If no algorithm is specified in the `decode()` function, the packages uses the algorithm in the JWT to decode tokens. This allows an attacker to create a HS256 (symmetric algorithm) JWT with the server's public key as secret, and the package will verify it as HS256 instead of RS256 (asymmetric algorithm).

## Recommendation

Upgrade to version 0.5.3 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/jwt-simple
Introduced in: 0Fixed in: 0.5.3
Fixnpm install jwt-simple@0.5.3

References