CVE-2025-13877 | nocobase up to 1.9.4/2.0.0-alpha.37 JWT Service jwt-service.ts API_KEY hard-coded key (EUVD-2025-200266)
A vulnerability was found in nocobase up to 1.9.4/2.0.0-alpha.37. It has been declared as problematic. The affected element is an unknown function of the file nocobase\packages\core\auth\src\base\jwt-service.ts of the component JWT Service. The manipulation of the argument API_KEY results in use of hard-coded cryptographic key
.
This vulnerability is reported as CVE-2025-13877. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.