THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-13877 (MEDIUM 5.6) — A vulnerability was detected in nocobase up to 1.9.4/2.0.0-alpha.37. The affected element is an unknown function of the file nocobase\packages\core\auth\src\base\jwt-service.ts of the component JWT Service. The manipulation of the argument API_KEY results in use of hard-coded cry

[NVD] CVE-2025-13877 (MEDIUM 5.6) — A vulnerability was detected in nocobase up to 1.9.4/2.0.0-alpha.37. The affected element is an unknown function of the file nocobase\packages\core\auth\src\base\jwt-service.ts of the component JWT Service. The manipulation of the argument API_KEY results in use of hard-coded cry

lownvdPublished 2025-12-02

CVE-2025-13877 CVSS: 5.6 MEDIUM Published: 2025-12-02T16:15:54.310

A vulnerability was detected in nocobase up to 1.9.4/2.0.0-alpha.37. The affected element is an unknown function of the file nocobase\packages\core\auth\src\base\jwt-service.ts of the component JWT Service. The manipulation of the argument API_KEY results in use of hard-coded cryptographic key . The attack can be launched remotel

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-13877