{"id":"CVE-2025-14261","summary":"Lack of entropy allows registered low-privileged users of Litmus to crack valid JWT tokens and gain admin privileges","details":"The Litmus platform uses JWT for authentication and authorization, but the secret being used for signing the JWT is only 6 bytes long at its core, which makes it extremely easy to crack.","modified":"2026-08-12T03:51:20.510704332Z","published":"2025-12-08T18:12:46.826Z","database_specific":{"cna_assigner":"JFROG","cwe_ids":["CWE-331"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/14xxx/CVE-2025-14261.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/14xxx/CVE-2025-14261.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-14261"},{"type":"ADVISORY","url":"https://research.jfrog.com/vulnerabilities/litmus-jwt-missing-entropy-elevation-jfsa-2025-001648159/"},{"type":"FIX","url":"https://github.com/litmuschaos/litmus/pull/5324"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/litmuschaos/litmus","events":[{"introduced":"0"},{"fixed":"5f4fb5efab59150441091f18dba2dd8d8724a1e9"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"3.23.0"}],"source":"AFFECTED_FIELD"}}],"versions":["3.22.0","3.21.0","3.20.0","3.19.0","3.18.0","3.17.0","3.16.0","3.15.0","3.14.0","3.13.0","3.12.0","3.11.0","3.10.0","3.9.0","3.8.0","3.7.0","3.6.1","3.6.0","3.5.0","3.4.0","3.3.0","3.2.0","3.1.0","3.0.0","3.0.0-beta12","3.0.0-beta11","3.0.0-beta10","3.0.0-beta9","3.0.0-beta8","3.0.0-beta7","3.0.0-beta6","3.0.0-beta5","3.0.0-beta4","3.0.0-beta3","3.0.0-beta2","3.0-beta0","2.13.0","2.12.0","2.11.0","2.10.0","2.9.0","2.8.0","2.7.0","2.6.0","2.5.0","2.4.0","2.3.0","2.1.0","2.0.0","2.0.0-RC1","2.0.0-Beta9","2.0.0-Beta8","2.0.0-Beta7","2.0.0-Beta6","2.0.0-Beta5","2.0.0-Beta4","2.0.0-Beta3","2.0.0-Beta2","2.0.0-Beta1","2.0.0-Beta0","1.9.0-RC1","1.8.0-RC1","1.6.0","1.5.0","1.4.0-RC1","1.3.0-RC1","1.2.0-RC1","1.1.0-RC1","1.0.0-RC1","0.9.0-RC1","0.8.0-RC1","0.7.0-RC1","0.7.0","0.6.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-14261.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H"}]}