CVE-2025-65945Auth0 node-jws HS256 verification bypass via secret lookup
What broke
auth0/node-jws below 3.2.3 and 4.0.1 verified HS256 JWTs incorrectly when the secret was resolved through a user-controlled lookup. An attacker who can influence which secret is chosen can produce a token that verifies. Patched in 3.2.3 and 4.0.1 (December 2025). Public EPSS around disclosure sat near 0.93 percent, which is why some trackers call it medium. The class is still "signature bypass."
Why it matters
node-jws sits under a lot of Node OIDC and API-auth code, including stacks that started from Auth0 samples. A medium CVSS on a JWT library is how "we only accept signed tokens" quietly becomes "we accept the attacker's HMAC." Pair it with CVE-2025-9485 (WordPress OAuth SSO JWT forgery) and CVE-2026-48558 (SimpleHelp alg:none) and you have the 2025-2026 JWT lesson: verifiers still fail the first test.
What to do
- Upgrade node-jws to 4.0.1 or 3.2.3. Search transitive deps, not only direct ones.
- Never let the token pick the HMAC secret. Resolve the key from a server-side kid map, then verify.
- Prefer RS256/ES256 with a JWKS endpoint over HS256 shared secrets for anything that crosses a trust boundary.
- See the JWT decoder and the validate a JWT recipe for the checks a verifier must not skip.
Sources
- NVD: CVE-2025-65945
- auth0/node-jws security advisory, December 2025