Executive brief
NocoBase is an open-source low-code database platform deployed via Docker containers. Docker deployments shipped with a publicly known default JWT (authentication token) secret, allowing attackers to forge valid login tokens and impersonate any user including administrators without needing legitimate credentials. An attacker can gain full control of the NocoBase instance, access all data, modify user accounts, and steal stored secrets.
Technical details
The vulnerability is an authentication bypass caused by hardcoded or publicly documented default JWT secrets in NocoBase's official Docker deployment configurations. An attacker can craft a valid JWT token using the known secret and a guessed or common userId (typically the administrator account), then use this forged token to bypass authentication and authorization checks entirely. The attack is network-accessible, requires no prior authentication or user interaction, and public proof-of-concept exploits are available. Successful exploitation allows the attacker to assume any user identity, access sensitive business data, create or delete users, and retrieve cloud storage credentials. The patch redesigns JWT key management to forbid public defaults, require explicit user-provided secrets or cryptographically secure random generation, and validate secret strength at startup.
Affected products
- NocoBase NocoBase <1.9.23, >=1.9.0-beta.1 <1.9.0-beta.18, >=2.0.0-alpha.1 <2.0.0-alpha.52
Timeline
- 2025-12-09: disclosed
- 2025-12-09: patched: Fixed in versions 1.9.23, 1.9.0-beta.18, and 2.0.0-alpha.52