Exploiting JWT Algorithm Confusion Attack

Exploit JWT algorithm confusion vulnerabilities by manipulating the alg header to switch from RS256 to HS256, set alg to none, or inject kid/jku/x5u headers to bypass signature verification.

mukul975 Updated 24.6k repo stars

File contents

mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/exploiting-jwt-algorithm-confusion-attack commit 673da1f3b0

Frequently asked questions

npx skillmds@latest add mukul975/exploiting-jwt-algorithm-confusion-attack