CVE-2025-47945
CRITICALDescription
Donetick an open-source app for managing tasks and chores. Prior to version 0.1.44, the application uses JSON Web Tokens (JWT) for authentication, but the signing secret has a weak default value. While the responsibility is left to the system administrator to change it, this approach is inadequate. The vulnerability is proven by existence of the issue in the live version as well. This issue can result in full account takeover of any user. Version 0.1.44 contains a patch.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| donetick | donetick |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-47945? +
How severe is CVE-2025-47945? +
What products are affected by CVE-2025-47945? +
How do I check if I'm vulnerable to CVE-2025-47945? +
Related Vulnerabilities
Allstar is a GitHub App to set and enforce security policies. In versions prior to 4.5, a vulnerability in Allstar’s …
Dpanel is a Docker visualization panel system which provides complete Docker management functions. The Dpanel service contains a hardcoded JWT …
Skype for Consumer Remote Code Execution Vulnerability
Windows Remote Desktop Services Remote Code Execution Vulnerability
In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default value. This could lead …
filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a …