Tag
critical
advisory
fast-jwt Library JWT Algorithm Confusion Vulnerability
2 rules 1 TTP 1 CVEThe fast-jwt library is vulnerable to JWT Algorithm Confusion via Whitespace-Prefixed RSA Public Key due to an incomplete fix for CVE-2023-48223, allowing attackers to bypass intended security measures by exploiting leading whitespace in the RSA public key, enabling attackers to sign arbitrary payloads that will be accepted by the verifier, potentially leading to privilege escalation.
jwt
algorithm-confusion
vulnerability
fast-jwt
nodejs
2r
1t
1c
critical
advisory
node-tesseract-ocr OS Command Injection Vulnerability
2 rules 1 TTP 5 IOCsThe node-tesseract-ocr npm package through version 2.2.1 is vulnerable to OS command injection due to improper sanitization of the file path parameter in the recognize() function, potentially allowing for arbitrary command execution.
command-injection
nodejs
tesseract-ocr
cve-2026-26832
2r
1t
5i