VDB
Sign up
HIGH8.1

GHSA-c8m8-3jcr-6rj5

FUXA has a hardcoded fallback JWT signing secret

Quick fix

GHSA-c8m8-3jcr-6rj5 — @frangoteam/fuxa: upgrade to the fixed version with the command below.

npm install @frangoteam/fuxa@1.3.0

Details

FUXA used a static fallback JWT signing secret (`frangoteam751`) when no `secretCode` was configured.

If authentication was enabled without explicitly setting a custom secret, an attacker who knew the default value could forge valid JWT tokens and bypass authentication.

This issue has been addressed in version 1.3.0 by removing the static fallback and generating a secure random secret when no `secretCode` is provided.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@frangoteam/fuxa
Introduced in: 0Fixed in: 1.3.0
Fixnpm install @frangoteam/fuxa@1.3.0

References