7.1
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
Description
The Litmus platform uses JWT for authentication and authorization, but the secret being used for signing the JWT is only 6 bytes long at its core, which makes it extremely easy to crack.
Basic Information
ID
CVE-2025-14261
Source
JFROG
Published
Dec 8, 2025 at 18:12
Modified
Dec 8, 2025 at 18:20
Affected Product
Vendor
Litmuschaos
Product
litmus
Affected Versions
Litmuschaos litmus 0