PT-2025-40251 · Kazaar · Kazaar

Published

2025-10-01

·

Updated

2025-10-01

·

CVE-2025-59685

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kazaar version 1.25.12
Description The software allows a JSON Web Token (JWT) with 'none' specified in the 'alg' field. This can potentially compromise the integrity of the authentication process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2025-59685

Affected Products

Kazaar