jsonwebtoken
Advanced tools
Changelog
9.0.1 - 2023-07-05
Changelog
9.0.0 - 2022-12-21
Breaking changes: See Migration from v8 to v9
Arbitrary File Write via verify function
- CVE-2022-23529Insecure default algorithm in jwt.verify() could lead to signature validation bypass
- CVE-2022-23540Insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC
- CVE-2022-23541Unrestricted key type could lead to legacy keys usage
- CVE-2022-23539Changelog
8.5.1 - 2019-03-18
Changelog
8.5.0 - 2019-02-20
Changelog
8.4.0 - 2018-11-14
Changelog
8.3.0 - 2018-06-11
Changelog
8.2.2 - 2018-05-30
Changelog
8.2.1 - 2018-04-05
Changelog
8.2.0 - 2018-03-02