vulns.co
/
mcp by GKData.io

Back to Checklists

JWT / session tokens

The payload is a claim list. The header is the attack. Verify what the server actually verifies.

Tags: jwt, ato, session

Checklist

  • Decode, do not trust: alg, kid, jku, x5u, typ, cty. iss/aud/exp/nbf/iat. role, tenant, email, email_verified.
  • alg confusion: none / None, RS256 to HS256 with the published PEM as HMAC secret. Server must accept it, not just decode.
  • kid / jku: Path, SQL, URL fetch. jku/x5u is SSRF plus a key you control.
  • Claim tamper: role, tenant_id, user_id, email_verified. Unsigned or weakly signed tokens only.
  • Refresh vs access: Logout must kill refresh. Rotation. Reuse detection.
  • Storage: localStorage XSS, parent-domain cookie, mobile WebView leak.

Back to Checklists