VDB
Sign up
CRITICAL

GHSA-vgrx-w6rg-8fqf

Forgeable Public/Private Tokens in jwt-simple

Quick fix

GHSA-vgrx-w6rg-8fqf — jwt-simple: upgrade to the fixed version with the command below.

npm install jwt-simple@0.3.1

Details

Affected versions of the `jwt-simple` package allow users to select what algorithm the server will use to verify a provided JWT. A malicious actor can use this behaviour to arbitrarily modify the contents of a JWT while still passing verification. For the common use case of the JWT, the end result is a complete authentication bypass with minimal effort.

## Recommendation

Update to version 0.3.1 or later.

Additionally, be sure to always specify an algorithm in calls to `.decode()`.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/jwt-simple
Introduced in: 0Fixed in: 0.3.1
Fixnpm install jwt-simple@0.3.1

References