JWT Signing Key Vulnerability in ArchiverSpaApi by Archiver
CVE-2025-35940
8.1HIGH
What is CVE-2025-35940?
The ArchiverSpaApi ASP.NET application is exposed due to a misconfiguration involving a hard-coded JSON Web Token (JWT) signing key. This flaw enables unauthenticated remote attackers to craft and utilize a valid JWT token, thereby gaining unauthorized access to sensitive URL endpoints within the application. As a result, this vulnerability poses serious risks to data integrity and confidentiality.
Affected Version(s)
Archiver 15.7 <= 15.8
