{"id":"GHSA-mv7p-34fv-4874","summary":"Authentication Bypass via Default JWT Secret in NocoBase docker-compose Deployments","details":"### Impact\n\nCVE-2025-13877 is an **authentication bypass vulnerability caused by insecure default JWT key usage** in NocoBase Docker deployments.\n\nBecause the official one-click Docker deployment configuration historically provided a **public default JWT key**, attackers can **forge valid JWT tokens without possessing any legitimate credentials**. By constructing a token with a known `userId` (commonly the administrator account), an attacker can directly bypass authentication and authorization checks.\n\nSuccessful exploitation allows an attacker to:\n\n- Bypass authentication entirely\n- Impersonate arbitrary users\n- Gain full administrator privileges\n- Access sensitive business data\n- Create, modify, or delete users\n- Access cloud storage credentials and other protected secrets\n\nThe vulnerability is **remotely exploitable**, requires **no authentication**, and **public proof-of-concept exploits are available**.  \nThis issue is functionally equivalent in impact to other JWT secret exposure vulnerabilities such as **CVE-2024-43441** and **CVE-2025-30206**.\n\nDeployments that used the default Docker configuration without explicitly overriding the JWT secret are affected.\n\n---\n\n### Patches\n\n✅ The vulnerability has been **fully patched** through a secure JWT key management redesign.\n\nThe remediation enforces the following security guarantees:\n\n- JWT secrets are no longer allowed to fall back to public default values.\n- Secrets must either:\n  - Be explicitly provided by the user, or\n  - Be securely generated using cryptographically strong randomness at first startup.\n- Generated secrets are persisted securely with restricted filesystem permissions.\n- Invalid or weak secret values immediately trigger a startup failure.\n\n✅ Fixed Versions:\n- **NocoBase ≥ 1.9.23**\n- **NocoBase ≥ 1.9.0-beta.18**\n- **NocoBase ≥ 2.0.0-alpha.52**\n\n---\n\n### Workarounds\n\nIf upgrading is not immediately possible, the following temporary mitigations **must** be performed to reduce risk:\n\n1. Explicitly set a **strong, randomly generated JWT secret** via environment variables `APP_KEY`.\n2. **Restart all running NocoBase instances** so the new secret takes effect.\n3. **Invalidate all existing JWT sessions**, forcing complete user re-authentication.\n4. Verify that **no default secret values** are present in:\n   - `docker-compose.yml`\n   - `.env` files\n   - Kubernetes Secrets\n\n---\n\n### References\n\n- **CVE Record:** CVE-2025-13877  \n- **VulDB Entry:** https://vuldb.com/?id.334033  \n- **Public Exploit Proof:**  \n  https://gist.github.com/H2u8s/f3ede60d7ecfe598ae452aa5a8fbb90d  \n\n- **Affected Default Docker Configurations:**  \n  - https://github.com/nocobase/nocobase/blob/main/docker/app-mysql/docker-compose.yml#L13  \n  - https://github.com/nocobase/nocobase/blob/main/docker/app-mariadb/docker-compose.yml#L13  \n  - https://github.com/nocobase/nocobase/blob/main/docker/app-postgres/docker-compose.yml#L11  \n  - https://github.com/nocobase/nocobase/blob/main/docker/app-sqlite/docker-compose.yml#L11  \n\n- **Official Deployment Documentation:**  \n  - https://docs.nocobase.com/welcome/getting-started/installation/docker-compose  \n  - https://v2.docs.nocobase.com/get-started/installation/docker","aliases":["CVE-2025-13877"],"modified":"2025-12-09T17:57:52.568117Z","published":"2025-12-09T17:42:53Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-12-09T17:42:53Z","nvd_published_at":null,"cwe_ids":["CWE-1320","CWE-321"]},"references":[{"type":"WEB","url":"https://github.com/nocobase/nocobase/security/advisories/GHSA-mv7p-34fv-4874"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-13877"},{"type":"WEB","url":"https://github.com/nocobase/nocobase/commit/de4292ea7847dd26c6306445091769f8b9ee96d5"},{"type":"WEB","url":"https://docs.nocobase.com/welcome/getting-started/installation/docker-compose"},{"type":"WEB","url":"https://gist.github.com/H2u8s/f3ede60d7ecfe598ae452aa5a8fbb90d"},{"type":"PACKAGE","url":"https://github.com/nocobase/nocobase"},{"type":"WEB","url":"https://github.com/nocobase/nocobase/blob/main/docker/app-mariadb/docker-compose.yml#L13"},{"type":"WEB","url":"https://github.com/nocobase/nocobase/blob/main/docker/app-mysql/docker-compose.yml#L13"},{"type":"WEB","url":"https://github.com/nocobase/nocobase/blob/main/docker/app-postgres/docker-compose.yml#L11"},{"type":"WEB","url":"https://github.com/nocobase/nocobase/blob/main/docker/app-sqlite/docker-compose.yml#L11"},{"type":"WEB","url":"https://v2.docs.nocobase.com/get-started/installation/docker"},{"type":"WEB","url":"https://vuldb.com/?ctiid.334033"},{"type":"WEB","url":"https://vuldb.com/?id.334033"},{"type":"WEB","url":"https://vuldb.com/?submit.692205"}],"affected":[{"package":{"name":"@nocobase/auth","ecosystem":"npm","purl":"pkg:npm/%40nocobase/auth"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.9.0"},{"fixed":"1.9.23"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 1.9.21","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-mv7p-34fv-4874/GHSA-mv7p-34fv-4874.json"}},{"package":{"name":"@nocobase/auth","ecosystem":"npm","purl":"pkg:npm/%40nocobase/auth"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.9.0-beta.18"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 1.9.0-beta.17","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-mv7p-34fv-4874/GHSA-mv7p-34fv-4874.json"}},{"package":{"name":"@nocobase/auth","ecosystem":"npm","purl":"pkg:npm/%40nocobase/auth"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.0.0-alpha.1"},{"fixed":"2.0.0-alpha.52"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-mv7p-34fv-4874/GHSA-mv7p-34fv-4874.json","last_known_affected_version_range":"\u003c= 2.0.0-alpha.51"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}]}