This is a heavily interactive web application, and JavaScript is required. Simple HTML interfaces are possible, but that is not what this is.
Post
PentesterLab
pentesterlab.com
did:plc:vsjziuri7y2hxzp3vnazcsoh
🔥 CVE-2026-23993: HarbourJwt JWT auth bypass via unknown alg.
Not just alg=none: unsupported alg => empty signature, so forged token header.payload. passes.
Write-up + fix: https://pentesterlab.com/blog/cve-2026-23993-harbourjwt-unknown-alg-jwt-bypass
2026-01-21T22:12:37.096Z