Popular JavaScript library can be hacked to allow attackers to gain access to user accounts


  • Node-forge cryptography library flaw (CVE-2025-12816) allowed signature and certificate validation bypass
  • CERT-CC warns of risks including bypassing authentication and signed data manipulation
  • Maintainers released version 1.3.2; developers are encouraged to update immediately

A popular JavaScript cryptography library is vulnerable in a way that could allow threat actors to break into user accounts. The library has since been updated and users are encouraged to move to the new version as soon as possible.

The flaw was found in the ‘node-forge’ package, a popular cryptography tool that provides functionality for things like encryption, decryption, hashing, digital signatures, TLS/SSL and key generation, all without the need for built-in modules.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top