CVE-2025-13877 is an authentication bypass vulnerability caused by insecure default JWT key usage in NocoBase Docker deployments.
Because the official one-click Docker deployment configuration historically provided a public default JWT key, attackers can forge valid JWT tokens without possessing any legitimate credentials. By constructing a token with a known userId (commonly the administrator account), an attacker can directly bypass authentication and authorization checks.
Successful exploitation allows an attacker to:
The vulnerability is remotely exploitable, requires no authentication, and public proof-of-concept exploits are available.
This issue is functionally equivalent in impact to other JWT secret exposure vulnerabilities such as CVE-2024-43441 and CVE-2025-30206.
Deployments that used the default Docker configuration without explicitly overriding the JWT secret are affected.
✅ The vulnerability has been fully patched through a secure JWT key management redesign.
The remediation enforces the following security guarantees:
✅ Fixed Versions:
If upgrading is not immediately possible, the following temporary mitigations must be performed to reduce risk:
APP_KEY.docker-compose.yml.env filesCVE Record: CVE-2025-13877
VulDB Entry: https://vuldb.com/?id.334033
Public Exploit Proof:
https://gist.github.com/H2u8s/f3ede60d7ecfe598ae452aa5a8fbb90d
Affected Default Docker Configurations:
Official Deployment Documentation:
{
"cwe_ids": [
"CWE-1320",
"CWE-321"
],
"github_reviewed": true,
"github_reviewed_at": "2025-12-09T17:42:53Z",
"nvd_published_at": null,
"severity": "MODERATE"
}