CVE-2025-13877Medium· 5.6▾ SunlitA vulnerability was detected in nocobase up to 1.9.4/2.0.0-alpha.37. The affected element is an unknown function of the file nocobase\packages\core\auth\src\base\jwt-service.ts of the component JWT Service. The manipulation of the argume…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 3.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
A vulnerability was detected in nocobase up to 1.9.4/2.0.0-alpha.37. The affected element is an unknown function of the file nocobase\packages\core\auth\src\base\jwt-service.ts of the component JWT Service. The manipulation of the argument API_KEY results in use of hard-coded cryptographic key . The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is described as difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-90510High· 8.3A security vulnerability has been detected in dromara orion-visor up to 2.5.7
CVE-2026-86241Medium· 4.3A weakness has been identified in liufee FeehiCMS up to 2.1.1
CVE-2025-6666Low· 2.0A vulnerability was determined in motogadget mo.lock Ignition Lock up to 20251125
CVE-2026-5622Low· 3.7A vulnerability was determined in hcengineering Huly Platform 0.7.382
CVE-2026-5527Medium· 5.3A weakness has been identified in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53
CVE-2026-8243Medium· 5.3A vulnerability was determined in Industrial Application Software IAS Canias ERP 8.03