CVE-2025-13877
medium
CVSS v3
5.6
CVSS v4 NEW
2.9
VIR risk
5.6
Description
Authentication Bypass via Default JWT Secret in NocoBase docker-compose Deployments
Predictions
Exploit likelihood
66%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| npm | @nocobase/auth | >=1.9.0,<1.9.23 | 1.9.23 |
| npm | @nocobase/auth | <1.9.0-beta.18 | 1.9.0-beta.18 |
| npm | @nocobase/auth | >=2.0.0-alpha.1,<2.0.0-alpha.52 | 2.0.0-alpha.52 |
References
- https://gist.github.com/H2u8s/f3ede60d7ecfe598ae452aa5a8fbb90d
- https://vuldb.com/?ctiid.334033
- https://vuldb.com/?id.334033
- https://vuldb.com/?submit.692205
- https://github.com/nocobase/nocobase/security/advisories/GHSA-mv7p-34fv-4874
- https://nvd.nist.gov/vuln/detail/CVE-2025-13877
- https://github.com/nocobase/nocobase/commit/de4292ea7847dd26c6306445091769f8b9ee96d5
- https://docs.nocobase.com/welcome/getting-started/installation/docker-compose
- https://github.com/nocobase/nocobase
- https://github.com/nocobase/nocobase/blob/main/docker/app-mariadb/docker-compose.yml#L13
- https://github.com/nocobase/nocobase/blob/main/docker/app-mysql/docker-compose.yml#L13
- https://github.com/nocobase/nocobase/blob/main/docker/app-postgres/docker-compose.yml#L11
- https://github.com/nocobase/nocobase/blob/main/docker/app-sqlite/docker-compose.yml#L11
- https://v2.docs.nocobase.com/get-started/installation/docker
CWEs
CWE-320 CWE-321
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.