PT-2025-48710 · Nocobase · Nocobase

28Hus

·

Published

2025-12-02

·

Updated

2025-12-09

·

CVE-2025-13877

CVSS v3.1

5.6

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions nocobase versions 1.9.4 and 2.0.0-alpha.37
Description A security issue exists in nocobase that allows for remote attacks with high complexity and difficult exploitability. The issue involves the manipulation of the API KEY argument within an unknown function in the file nocobasepackagescoreauthsrcbasejwt-service.ts of the JWT Service component, leading to the use of a hard-coded cryptographic key. The exploit is publicly available. The vendor was notified but did not respond.
Recommendations Versions prior to 1.9.4 and 2.0.0-alpha.37 should be updated.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-13877

Affected Products

Nocobase