Intel

AIKIDO-2025-10399

jwt is vulnerable to Insufficient Verification of Data Authenticity

Insufficient Verification of Data Authenticity Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

20

Low Risk

This Affects:

Rubyjwt
0.0.1 - 3.0.0
Fixed in 3.1.0

TL;DR

Affected versions of this package contain a design flaw that can lead to unverified JWT claims, allowing attackers to bypass authentication by tampering with the token payload and presenting malicious JWTs that may be accepted without proper claim validation, potentially leading to unauthorized access or privilege escalation.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

jwt is vulnerable to Insufficient Verification of Data Authenticity in versions 0.0.1 - 3.0.0.

How to fix this

Upgrade the jwt library to the patch version.