All fixes

Replace a weak JWT signing secret

jwt-weak-secret

Your JWT signing secret is short enough to crack offline. Whoever recovers it can mint a token for any account. Rotate to a long random secret.

Why this matters

Your site's JWT token is signed with a weak or guessable secret. Anyone can forge valid authentication tokens and impersonate any user on your site.

Express

  1. 1 Rotate the JWT secret immediately
  2. 2 Generate a strong random secret (at least 256 bits)
  3. 3 Store it in environment variables, never in code
bash
# Generate a strong secret
node -e "console.log(require('crypto').randomBytes(64).toString('hex'))"

# .env
JWT_SECRET=<paste the generated secret>

# In code
const jwt = require('jsonwebtoken');
const token = jwt.sign(payload, process.env.JWT_SECRET);

Does your app still have this?

Scan your domain