CVE-2025-13877 — @nocobase/auth
Fix: nocobase/nocobase@de4292eCVE-2025-13877 is a CWE-320 vulnerability in @nocobase/auth. A fix is available for @nocobase/auth — see the affected versions and patch details below.
Authentication Bypass via Default JWT Secret in NocoBase docker-compose Deployments
Exploitation Status
Proof-of-concept exploit code exists
- CISA’s SSVC triage found public proof-of-concept exploit code for this CVE, though no confirmed active exploitation.
Exploitation and automatability from CISA’s SSVC triage for CVE-2025-13877.
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
Real-World Exposure
How broadly this vulnerability is actually deployed: weekly install volume shows current usage, and reverse-dependency count shows how many other packages break if it stays unpatched.
@nocobase/authnpmDescription
Impact
CVE-2025-13877 is an authentication bypass vulnerability caused by insecure default JWT key usage in NocoBase Docker deployments.
Because the official one-click Docker deployment configuration historically provided a public default JWT key, attackers can forge valid JWT tokens without possessing any legitimate credentials. By constructing a token with a known userId (commonly the administrator account), an attacker can directly bypass authentication and authorization checks.
Successful exploitation allows an attacker to:
- Bypass authentication entirely
- Impersonate arbitrary users
- Gain full administrator privileges
- Access sensitive business data
- Create, modify, or delete users
- Access cloud storage credentials and other protected secrets
The vulnerability is remotely exploitable, requires no authentication, and public proof-of-concept exploits are available.
This issue is functionally equivalent in impact to other JWT secret exposure vulnerabilities such as CVE-2024-43441 and CVE-2025-30206.
Deployments that used the default Docker configuration without explicitly overriding the JWT secret are affected.
Patches
✅ The vulnerability has been fully patched through a secure JWT key management redesign.
The remediation enforces the following security guarantees:
- JWT secrets are no longer allowed to fall back to public default values.
- Secrets must either:
- Be explicitly provided by the user, or
- Be securely generated using cryptographically strong randomness at first startup.
- Generated secrets are persisted securely with restricted filesystem permissions.
- Invalid or weak secret values immediately trigger a startup failure.
✅ Fixed Versions:
- NocoBase ≥ 1.9.23
- NocoBase ≥ 1.9.0-beta.18
- NocoBase ≥ 2.0.0-alpha.52
Workarounds
If upgrading is not immediately possible, the following temporary mitigations must be performed to reduce risk:
- Explicitly set a strong, randomly generated JWT secret via environment variables
APP_KEY. - Restart all running NocoBase instances so the new secret takes effect.
- Invalidate all existing JWT sessions, forcing complete user re-authentication.
- Verify that no default secret values are present in:
docker-compose.yml.envfiles- Kubernetes Secrets
References
-
CVE Record: CVE-2025-13877
-
VulDB Entry: https://vuldb.com/?id.334033
-
Public Exploit Proof:
https://gist.github.com/H2u8s/f3ede60d7ecfe598ae452aa5a8fbb90d -
Affected Default Docker Configurations:
- https://github.com/nocobase/nocobase/blob/main/docker/app-mysql/docker-compose.yml#L13
- https://github.com/nocobase/nocobase/blob/main/docker/app-mariadb/docker-compose.yml#L13
- https://github.com/nocobase/nocobase/blob/main/docker/app-postgres/docker-compose.yml#L11
- https://github.com/nocobase/nocobase/blob/main/docker/app-sqlite/docker-compose.yml#L11
-
Official Deployment Documentation:
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 📦npm | @nocobase/auth | ≥ 1.9.0&&< 1.9.23 | 1.9.23npm install @nocobase/auth@1.9.23 |
| 📦npm | @nocobase/auth | all versions | 1.9.0-beta.18npm install @nocobase/auth@1.9.0-beta.18 |
| 📦npm | @nocobase/auth | ≥ 2.0.0-alpha.1&&< 2.0.0-alpha.52 | 2.0.0-alpha.52npm install @nocobase/auth@2.0.0-alpha.52 |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for @nocobase/auth, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update @nocobase/auth to 1.9.23 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2025-13877 is resolved across your whole dependency graph.
Workarounds
If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.
How O3 protects you
O3 Security's impact-aware SCA analyses which vulnerable code paths your application actually calls, so a match like CVE-2025-13877 can be triaged on real exposure rather than presence alone.
Tailored to CVE-2025-13877. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.
Frequently Asked Questions
Is CVE-2025-13877 in your dependencies?
O3 Security finds CVE-2025-13877 across npm dependencies, including transitive ones, and its impact-aware SCA ranks findings by whether your code actually calls the vulnerable path.