CVE-2025-65945
Last modified
CVE-2025-65945 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper signature verification vulnerability when using the HS256 algorithm under specific conditions. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper signature verification vulnerability when using the HS256 algorithm under specific conditions. Applications are affected when they use the jws.createVerify() function for HMAC algorithms and use user-provided data from the JSON Web Signature protected header or payload in HMAC secret lookup routines, which can allow attackers to bypass signature verification. This issue has been patched in versions 3.2.3 and 4.0.1.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Auth0 | Node-Jws | < 3.2.3 |
| Auth0 | Node-Jws | 4.0.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-65945?
How severe is CVE-2025-65945?
How do I fix CVE-2025-65945?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-65939Rejected reason: Not used
- CVE-2025-6594Improper Neutralization of Input During Web Page Generation …4.7
- CVE-2025-65940Rejected reason: Not used
- CVE-2025-65941Rejected reason: Not used
- CVE-2025-65942VictoriaMetrics is a scalable solution for monitoring and ma…2.7
- CVE-2025-65944Sentry-Javascript is an official Sentry SDKs for JavaScript.…5.1
- CVE-2025-65946Roo Code is an AI-powered autonomous coding agent that lives…8.1
- CVE-2025-65947thread-amount is a tool that gets the amount of threads in t…8.7
- CVE-2025-6595Improper Neutralization of Input During Web Page Generation …4.7
- CVE-2025-65950WBCE CMS is a content management system. In versions 1.6.4 a…8.8
- CVE-2025-65951Inside Track / Entropy Derby is a research-grade horse-racin…8.7
- CVE-2025-65952Console is a network used to control Gorilla Tag mods' users…8.7
Are you affected by CVE-2025-65945?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
