
Proof of Concept for CVE-2025-54887
This repository contains Proof-of-Concept (PoC) exploit for CVE-2025-54887.
This is a vulnerability in ruby-jwe (version <= 1.1.0) where the authentication tag of encrypted JWEs can be brute forced, which may result in loss of confidentiality and provide ways to craft arbitrary JWEs.
Writeup: blog_link
Demonstration video: video_link