Description
CVE-2025-13877 is an authentication bypass vulnerability caused by insecure default JWT key usage in NocoBase Docker deployments.
Because the official one-click Docker deployment configuration historically provided a public default JWT key, attackers can forge valid JWT tokens without possessing any legitimate credentials.
Recommendation
Update the @nocobase/auth package to the latest compatible version. Followings are version details:
Affected version(s): **>= 2.0.0-alpha.1, <= 2.0.0-alpha.51 <= 1.9.0-beta.17 >= 1.9.0, <= 1.9.21** Patched version(s): **2.0.0-alpha.52 1.9.0-beta.18 1.9.23**
References
Could your website be exposed too?
SmartScanner can check your website for Authentication Bypass via Default JWT Secret in NocoBase docker-compose Deployments and gives you actionable findings to investigate.
Start a free scanRelated Issues
- FUXA has JWT Authentication Bypass via HTTP Referer header spoofing - CVE-2025-69985
- OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover - CVE-2026-44720
- hemmelig allows SSRF Filter bypass via Secret Request functionality - CVE-2025-69206
- Misskey has a login rate limit bypass via spoofed X-Forwarded-For header - CVE-2025-66482


