Tag
critical
advisory
Authentication Bypass via HMAC Key Confusion in python-jose
2 CVEsThe python-jose library version 3.5.0 and earlier fails to validate asymmetric keys during HMAC initialization, allowing attackers with a public key to forge HS256 JWT tokens.
python-jose
authentication-bypass
jwt-forgery
dependency-vulnerability
2c
critical
advisory
PraisonAI Platform Vulnerable to JWT Forgery via Hardcoded Default Secret
2 rules 4 TTPs 3 IOCsThe `praisonai-platform` package, versions 0.1.4 and below, is critically vulnerable to authentication bypass and privilege escalation due to a hardcoded default JWT signing secret (`dev-secret-change-me`) that is inadvertently enabled in default deployments, allowing an unauthenticated attacker to forge JWTs and impersonate any user.
praisonai-platform <= 0.1.4
authentication-bypass
hardcoded-credentials
jwt-forgery
python
supply-chain
misconfiguration
2r
4t
3i