< Back

JFSA-2025-001648159 - Litmus Chaos JWT Missing Entropy Privilege Escalation

CVE-2025-14261 | CVSS 7.1

JFrog Severity:high

Discovered ByNatan Nehoraiof the JFrog Security Research Team

Published 8 Dec, 2025 | Last updated 8 Dec, 2025

Lack of entropy allows registered low-privileged users of Litmus to crack valid JWT tokens and gain admin privileges

Litmuschaos:litmus

(,3.23.0)

The Litmus platform uses JWT for authentication and authorization, but the secret being used for signing the JWT is only 6 bytes long at its core, which makes it extremely easy to crack.

No PoC is supplied for this issue

No mitigations are supplied for this issue

Fix PR

< Back