JWT Attacks

Hunt JSON Web Token (JWT) vulnerabilities — alg=none bypass, RS256→HS256 key confusion, weak HMAC secret cracking, kid path traversal, JWKS injection, jku/x5u header attacks, embedded JWK confusion, expired-token acceptance, claim mutability, and token replay. Use when an app uses JWT for authentication or stateless sessions.

0xGhostCAT Updated

File contents

0xGhostCAT/claude-ai-cyber-security-skills/tree/main/skills/19-jwt-attacks commit fcb48cf475

Frequently asked questions

npx skillmds@latest add 0xghostcat/jwt-attacks