Vulnerability library
Security checkDecember 09, 2025

Authentication Bypass via Default JWT Secret in NocoBase docker-compose Deployments

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Medium severitynpm@nocobase/auth

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

CVE-2025-13877 is an authentication bypass vulnerability caused by insecure default JWT key usage in NocoBase Docker deployments.

Because the official one-click Docker deployment configuration historically provided a public default JWT key, attackers can forge valid JWT tokens without possessing any legitimate credentials.

Recommendation

Update the @nocobase/auth package to the latest compatible version. Followings are version details:

  • Affected version(s): **>= 2.0.0-alpha.1, <= 2.0.0-alpha.51 <= 1.9.0-beta.17 >= 1.9.0, <= 1.9.21**
  • Patched version(s): **2.0.0-alpha.52 1.9.0-beta.18 1.9.23**

References

Could your website be exposed too?

SmartScanner can check your website for Authentication Bypass via Default JWT Secret in NocoBase docker-compose Deployments and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated December 09, 2025