jsonwebtoken before 9.0.0 can be bypassed by a malicious actor if the secretOrPublicKey can be controlled. An attacker could forge a JWT token and pass verification when the key can be set to an object with a toString function.
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free