Replace a weak JWT signing secret
jwt-weak-secret
Your JWT signing secret is short enough to crack offline. Whoever recovers it can mint a token for any account. Rotate to a long random secret.
Why this matters
Your site's JWT token is signed with a weak or guessable secret. Anyone can forge valid authentication tokens and impersonate any user on your site.
Frameworks
Express
- 1 Rotate the JWT secret immediately
- 2 Generate a strong random secret (at least 256 bits)
- 3 Store it in environment variables, never in code
bash
# Generate a strong secret
node -e "console.log(require('crypto').randomBytes(64).toString('hex'))"
# .env
JWT_SECRET=<paste the generated secret>
# In code
const jwt = require('jsonwebtoken');
const token = jwt.sign(payload, process.env.JWT_SECRET);Does your app still have this?
Scan your domain