Description
Ever Gauzy v0.281.9 contains a JWT authentication vulnerability that allows attackers to exploit weak HMAC secret key implementation. Attackers can leverage the exposed JWT token to authenticate and gain unauthorized access with administrative permissions.
Problem types
Improper Verification of Cryptographic Signature
Product status
Credits
nu11secur1ty
References
www.exploit-db.com/exploits/51354 (ExploitDB-51354)
github.com/ever-co/ever-gauzy (Official Product Homepage)
www.vulncheck.com/...authentication-weakness-via-hmac-secret (VulnCheck Advisory: Ever Gauzy v0.281.9 JWT Authentication Weakness via HMAC Secret)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.