Vulnerabilities/

Authentication Bypass via Default JWT Secret in NocoBase docker-compose Deployments

Severity:
Medium

Description

CVE-2025-13877 is an authentication bypass vulnerability caused by insecure default JWT key usage in NocoBase Docker deployments.

Because the official one-click Docker deployment configuration historically provided a public default JWT key, attackers can forge valid JWT tokens without possessing any legitimate credentials.

Recommendation

Update the @nocobase/auth package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@nocobase/auth
Anything's wrong? Let us know Last updated on December 09, 2025