HIGH
GHSA-8v5f-hp78-jgxq
Signature Verification Bypass in jwt-simple
Quick fix
GHSA-8v5f-hp78-jgxq — jwt-simple: upgrade to the fixed version with the command below.
npm install jwt-simple@0.5.3Details
Versions of `jwt-simple` prior to 0.5.3 are vulnerable to Signature Verification Bypass. If no algorithm is specified in the `decode()` function, the packages uses the algorithm in the JWT to decode tokens. This allows an attacker to create a HS256 (symmetric algorithm) JWT with the server's public key as secret, and the package will verify it as HS256 instead of RS256 (asymmetric algorithm).
## Recommendation
Upgrade to version 0.5.3 or later.
Are you affected?
Enter the version of the package you're using.