# jose@4.15.9 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:17:14.000Z
- Files reviewed: 246
- Findings: 10 medium, 4 low severity findings
- Report: https://security.togoder.click/npm/jose@4.15.9
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package jose@4.15.9 on Oct 6, 2026. An AI review of 246 source files produced 10 medium, 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Insecure JWT implementation (algorithm: none)

Finding ID: `NPS-B6FB0FD50905`

File: `dist/browser/jwt/unsecured.js:8`

The UnsecuredJWT class intentionally produces and accepts JWTs with the 'alg': 'none' header, meaning no signature is applied. This allows anyone to forge or tamper with tokens. While the class name makes the intent explicit, exporting/using this in production authentication flows would be a critical security weakness. The decode method also validates that 'alg' is 'none', but that does not mitigate the forgery risk inherent to unsecured JWTs.

### [medium] Missing signature verification

Finding ID: `NPS-CA27A9B97CE1`

File: `dist/browser/jwt/unsecured.js:18`

The decode method explicitly rejects any token that has a non-empty signature (signature !== ''). This means tokens signed with real algorithms are refused, and only unsigned tokens are accepted. Any application relying on this for authorization is trivially bypassable.

### [medium] Broken/incorrect code with rewritten variable names

Finding ID: `NPS-7784E4C9D3AD`

File: `dist/browser/lib/aesgcmkw.js:6`

The `wrap` function destructures `{ ciphertext: encryptedKey, tag }` from `encrypt(...)` but references undefined variables `encrypted`, `cek`, and `iv` in the return statement (the parameter is `cek`, `iv` is never assigned from `generateIv`). The import is `generate` but `generateIv` is called. The `unwrap` function calls `iv` and `tag` and `jweAlgorithm` which are not defined in scope. This code appears mangled/rewritten and would not run as-is; such tampering is suspicious and could hide alterations from the original upstream library.

### [medium] Cryptographic implementation tampering

Finding ID: `NPS-DD62554AA851`

File: `dist/browser/lib/aesgcmkw.js:6`

This file implements AES-GCM key wrapping for JWE. The code references ciphertext under a renamed alias (`encryptedKey`) and returns an undefined `encrypted` property. Altering key-wrapping logic in crypto libraries can weaken or subvert encryption. While no explicit exfiltration is visible, the mangled crypto flow is a red flag warranting review against the official upstream (e.g., jose) version.

### [medium] Network request without explicit protocol restriction

Finding ID: `NPS-40AC89A4D231`

File: `dist/browser/runtime/fetch_jwks.js:10`

The code fetches using url.href without validating that the protocol is https. An attacker-controlled URL could use http, file, or other schemes supported by fetch, potentially leading to local file access or cleartext transmission of sensitive data.

### [medium] Broken/incorrect code with rewritten variable names

Finding ID: `NPS-7784E4C9D3AD`

File: `dist/node/esm/lib/aesgcmkw.js:6`

The `wrap` function destructures `{ ciphertext: encryptedKey, tag }` from `encrypt(...)` but references undefined variables `encrypted`, `cek`, and `iv` in the return statement (the parameter is `cek`, `iv` is never assigned from `generateIv`). The import is `generate` but `generateIv` is called. The `unwrap` function calls `iv` and `tag` and `jweAlgorithm` which are not defined in scope. This code appears mangled/rewritten and would not run as-is; such tampering is suspicious and could hide alterations from the original upstream library.

### [medium] Cryptographic implementation tampering

Finding ID: `NPS-DD62554AA851`

File: `dist/node/esm/lib/aesgcmkw.js:6`

This file implements AES-GCM key wrapping for JWE. The code references ciphertext under a renamed alias (`encryptedKey`) and returns an undefined `encrypted` property. Altering key-wrapping logic in crypto libraries can weaken or subvert encryption. While no explicit exfiltration is visible, the mangled crypto flow is a red flag warranting review against the official upstream (e.g., jose) version.

### [medium] Weak cryptographic algorithm support

Finding ID: `NPS-D8A87025BC1B`

File: `dist/node/esm/runtime/rsaes.js:19`

The code supports RSA1_5 (PKCS#1 v1.5 padding) which is considered cryptographically weak and vulnerable to padding oracle attacks (e.g., Bleichenbacher). While this is a standards compliance choice, its presence increases risk if used in production.

### [medium] SHA-1 usage

Finding ID: `NPS-FF2D35CE2903`

File: `dist/node/esm/runtime/rsaes.js:30`

The 'RSA-OAEP' algorithm maps to SHA-1 for OAEP hashing. SHA-1 is deprecated and considered weak for cryptographic purposes.

### [medium] Malformed/hallucinated code with cryptographic verification logic

Finding ID: `NPS-ABE39CBF4A8F`

File: `dist/node/esm/runtime/verify.js:6`

The provided file claims to be from a package registry JavaScript module (dist/node/esm/runtime/verify.js) and imports legitimate-looking crypto utilities (crypto, promisify, sign, getVerifyKey). However, the code contains severe syntactic and semantic errors that make it non-functional: a stray `crypto.verify.length > 4 &&` expression concatenated with `oneShotCallback` inside the if condition; a call to `nodeDigest(alg)` that is assigned to `algorithm` without invocation context; `crypto.timingSafeEqual(actual, expected)` is called with two arguments but only one is supplied in the malformed expression; and the `findings.line` schema value is broken. This strongly suggests the file is either artificially generated, corrupted, or intentionally obfuscated to hide the true behavior of the module. Cryptographic verification code is frequently targeted for tampering in supply-chain attacks because a subtly altered comparison or key handling can make signature verification always succeed or leak private material. Here the odd `crypto.verify.length > 4` check (inspecting function arity) is a known technique to detect patched/proxied versions of `crypto.verify` and change behavior conditionally, which is suspicious in a package that is supposedly just performing standard DSA verification.

### [low] AbortController and timing behavior

Finding ID: `NPS-A255032E989D`

File: `dist/browser/runtime/fetch_jwks.js:4`

The timeout uses AbortController when available; if not available, no timeout is enforced, which could allow the request to hang indefinitely. This is a robustness concern rather than a direct malicious pattern.

### [low] Suspicious network request

Finding ID: `NPS-410E6F8145DA`

File: `dist/browser/runtime/fetch_jwks.js:10`

The function performs an HTTP fetch to a caller-provided URL using the global fetch API. While this is expected for a JWKS fetcher, the use of redirect: 'manual' prevents following redirects, which is a good security practice to avoid SSRF via redirects. However, the URL is fully controlled by the caller and no allowlist or validation is performed, which could be abused if untrusted input reaches this function.

### [low] cryptographic key parsing

Finding ID: `NPS-0D4B6CCA584A`

File: `dist/node/esm/runtime/jwk_to_key.js`

This file converts JWK (JSON Web Key) objects into Node.js KeyObject instances. It uses standard crypto APIs (createPrivateKey, createPublicKey, createSecretKey) and ASN.1 DER encoding for RSA, EC, and OKP keys. All operations are local, deterministic, and contain no network, filesystem, or process spawning behavior.

### [low] No dynamic exfiltration, credential harvesting, or shell execution detected

Finding ID: `NPS-F17CCC6B6905`

File: `dist/node/esm/runtime/verify.js`

The file does not import child_process, fs write operations outside scope, http/https network clients, eval/Function, or reference known credential file paths (.npmrc, .ssh, .aws, etc.). No install-time or import-time side effects beyond defining a verify function were observed, though the malformed top-level `if` does execute at import time.

## Files reviewed

- `dist/browser/jwt/unsecured.js` (medium): The file implements intentionally unsecured (unsigned, 'alg: none') JWT encoding/decoding, which is a known insecure pattern but contains no evidence of data exfiltration, credential harvesting, obfuscation, or other malicious behavior.
- `dist/browser/lib/aesgcmkw.js` (medium): No direct malicious behavior (no network calls, env harvesting, eval, process spawning, or install hooks) is present. However, the file is a mangled/modified cryptographic key-wrapping implementation with undefined variables and renamed tokens compared to typical upstream code, which is suspicious for a crypto module and should be diffed against the legitimate upstream source.
- `dist/browser/runtime/fetch_jwks.js` (medium): The code is a straightforward JWKS fetcher with no clear malicious patterns, but it lacks URL scheme validation and protocol enforcement, which are minor security hardening concerns.
- `dist/node/esm/lib/aesgcmkw.js` (medium): No direct malicious behavior (no network calls, env harvesting, eval, process spawning, or install hooks) is present. However, the file is a mangled/modified cryptographic key-wrapping implementation with undefined variables and renamed tokens compared to typical upstream code, which is suspicious for a crypto module and should be diffed against the legitimate upstream source.
- `dist/node/esm/runtime/rsaes.js` (medium): The code implements standard RSA encryption/decryption utilities without malicious patterns, but supports weak cryptographic padding (RSA1_5) and SHA-1 hashing, which could lead to insecure implementations if misused.
- `dist/node/esm/runtime/verify.js` (medium): The file is not clearly malicious but contains malformed, non-functional cryptographic verification code with a suspicious arity check on crypto.verify, which is a known tamper-detection/patching technique and warrants further review of the surrounding package.
- `dist/browser/index.js` (safe): This file only contains static re-exports of cryptographic functions from local modules, with no suspicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or install-time behavior.
- `dist/browser/jwe/compact/decrypt.js` (safe): No malicious patterns detected
- `dist/browser/jwe/compact/encrypt.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/jwe/flattened/decrypt.js` (safe): No malicious patterns detected; this is a standard JWE flattened decryption implementation with proper input validation and no exfiltration, code execution, or suspicious behavior.
- `dist/browser/jwe/flattened/encrypt.js` (safe): This is a standard JWE (JSON Web Encryption) implementation from the jose library; no malicious patterns, data exfiltration, credential harvesting, obfuscation, or process spawning were detected.
- `dist/browser/jwe/general/decrypt.js` (safe): No malicious patterns detected; the code implements standard JWE general decryption logic with proper input validation and error handling.
- `dist/browser/jwe/general/encrypt.js` (safe): No malicious patterns detected; this is a legitimate JWE General JSON encryption implementation from the jose library.
- `dist/browser/jwk/embedded.js` (safe): No malicious patterns detected
- `dist/browser/jwk/thumbprint.js` (safe): No malicious patterns detected
- `dist/browser/jwks/local.js` (safe): The code is a legitimate JWKS local key set implementation with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
- `dist/browser/jwks/remote.js` (safe): No malicious patterns detected; the code is a standard JWKS remote key set implementation for JOSE/JWT verification with expected network fetching and caching behavior.
- `dist/browser/jws/compact/sign.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/jws/compact/verify.js` (safe): No malicious patterns detected; the code is a standard JWS compact verification implementation.
- `dist/browser/jws/flattened/sign.js` (safe): This is a legitimate JWS signing implementation from the jose library with no malicious patterns detected.
- `dist/browser/jws/flattened/verify.js` (safe): No malicious patterns detected; the code is a standard JWS flattened verification implementation with proper validation and no exfiltration, code execution, or process spawning.
- `dist/browser/jws/general/sign.js` (safe): No malicious patterns detected; this file implements JWS General Serialization using only in-package cryptographic signing logic and standard error handling.
- `dist/browser/jws/general/verify.js` (safe): No malicious patterns detected
- `dist/browser/jwt/decrypt.js` (safe): This JWT decryption module contains only legitimate cryptographic verification logic with no malicious patterns detected.
- `dist/browser/jwt/encrypt.js` (safe): No malicious patterns detected; the code is a straightforward JWT encryption utility with standard header and key management methods.
- `dist/browser/jwt/produce.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/jwt/sign.js` (safe): No malicious patterns detected
- `dist/browser/jwt/verify.js` (safe): No malicious patterns detected
- `dist/browser/key/export.js` (safe): No malicious patterns detected; the file only re-exports key format conversion functions without any exfiltration, obfuscation, or execution of external code.
- `dist/browser/key/generate_key_pair.js` (safe): The file is a simple wrapper that re-exports a key generation function with no suspicious behavior, network access, file system manipulation, or dynamic code execution.
- `dist/browser/key/generate_secret.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/key/import.js` (safe): No malicious patterns detected; the code is a standard JOSE key import module performing input validation and cryptographic key conversion without network, filesystem, or dynamic execution behavior.
- `dist/browser/lib/buffer_utils.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/lib/cek.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/lib/check_iv_length.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/lib/check_key_type.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/lib/check_p2s.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/lib/crypto_key.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/lib/decrypt_key_management.js` (safe): No malicious patterns detected; the code is a standard JWE key management decryption implementation with proper input validation and no data exfiltration, credential harvesting, or dynamic execution.
- `dist/browser/lib/encrypt_key_management.js` (safe): No malicious patterns detected; the code implements standard JWE key management algorithms without data exfiltration, credential harvesting, obfuscation, or suspicious network/process activity.
- `dist/browser/lib/epoch.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/lib/format_pem.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/lib/invalid_key_input.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/lib/is_disjoint.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/lib/is_object.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/lib/iv.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/lib/jwt_claims_set.js` (safe): No malicious patterns detected
- `dist/browser/lib/secs.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/lib/validate_algorithms.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/lib/validate_crit.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/runtime/aeskw.js` (safe): No malicious patterns detected; the code implements AES key wrapping using standard WebCrypto APIs and only imports local modules.
- `dist/browser/runtime/asn1.js` (safe): No malicious patterns detected; the code is a standard ASN.1/PEM key conversion utility using Web Crypto API with no data exfiltration, dynamic code execution, or suspicious behavior.
- `dist/browser/runtime/base64url.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/runtime/bogus.js` (safe): No malicious patterns detected; the file exports a static array of WebCrypto algorithm identifiers with no executable or suspicious behavior.
- `dist/browser/runtime/check_cek_length.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/runtime/check_key_length.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/runtime/decrypt.js` (safe): No malicious patterns detected; the code implements standard JWE decryption routines using WebCrypto APIs without any data exfiltration, obfuscation, or suspicious behavior.
- `dist/browser/runtime/digest.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/runtime/ecdhes.js` (safe): This is a standard ECDH key derivation implementation using WebCrypto with no malicious patterns, data exfiltration, or suspicious behavior.
- `dist/browser/runtime/encrypt.js` (safe): No malicious patterns detected; the code implements standard JWE content encryption using the Web Crypto API without exfiltration, obfuscation, or suspicious behavior.
- `dist/browser/runtime/generate.js` (safe): No malicious patterns detected; the code implements standard JOSE/JWK key generation using the Web Crypto API.
- `dist/browser/runtime/get_sign_verify_key.js` (safe): The code is a standard JWT key handling function with no malicious patterns, external requests, or dynamic execution.
- `dist/browser/runtime/is_key_like.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/runtime/jwk_to_key.js` (safe): No malicious patterns detected; the code is a legitimate JWK to CryptoKey conversion utility from the jose library.
- `dist/browser/runtime/key_to_jwk.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/runtime/pbes2kw.js` (safe): No malicious patterns detected; this is a legitimate PBES2-KW cryptographic implementation for JWE using WebCrypto PBKDF2 and AES-KW.
- `dist/browser/runtime/random.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/runtime/rsaes.js` (safe): No malicious patterns detected; the code appears to be a legitimate implementation of RSA-OAEP encryption/decryption using the WebCrypto API.
- `dist/browser/runtime/runtime.js` (safe): No malicious patterns detected
- `dist/browser/runtime/sign.js` (safe): No malicious patterns detected
- `dist/browser/runtime/subtle_dsa.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/runtime/subtle_rsaes.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/runtime/timing_safe_equal.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/runtime/verify.js` (safe): No malicious patterns detected; the file implements standard JWT signature verification using WebCrypto.
- `dist/browser/runtime/webcrypto.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/runtime/zlib.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/util/base64url.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/util/decode_jwt.js` (safe): This is a standard JWT payload decoder with no malicious patterns, network activity, file system access, or dynamic code execution.
- `dist/browser/util/decode_protected_header.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/browser/util/errors.js` (safe): No malicious patterns detected; file only defines JOSE/JWT/JWE/JWS error classes with standard error properties and no I/O, network, process, eval, or credential access.
- `dist/browser/util/runtime.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/node/cjs/index.js` (safe): No malicious patterns detected; this is a standard JOSE/JWT library entry point that re-exports cryptographic functions without any suspicious behavior.
- `dist/node/cjs/jwe/compact/decrypt.js` (safe): No malicious patterns detected; the code is a standard compact JWE decryption wrapper that parses and delegates decryption without any exfiltration, obfuscation, or process execution behavior.
- `dist/node/cjs/jwe/compact/encrypt.js` (safe): No malicious patterns detected; the code is a straightforward JWE CompactEncrypt wrapper delegating to FlattenedEncrypt with no network, filesystem, process, or dynamic execution activity.
- `dist/node/cjs/jwe/flattened/decrypt.js` (safe): No malicious patterns detected; the code is a standard JWE decryption implementation using well-known helper modules without any data exfiltration, environment harvesting, obfuscation, or other security red flags.
- `dist/node/cjs/jwe/flattened/encrypt.js` (safe): The file implements standard JWE Flattened encryption logic using cryptographic primitives from internal modules and does not contain any malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or process spawning.
- `dist/node/cjs/jwe/general/decrypt.js` (safe): No malicious patterns detected in the provided JWE decryption module; it only performs input validation and delegates to a flattened decryption function.
- `dist/node/cjs/jwe/general/encrypt.js` (safe): No malicious patterns detected; the code implements standard JWE General JSON Serialization encryption logic without exfiltration, credential harvesting, obfuscation, or process execution.
- `dist/node/cjs/jwk/embedded.js` (safe): No malicious patterns detected; the code safely imports and validates an embedded JWK for JWS verification without exfiltration, dynamic execution, or process spawning.
- `dist/node/cjs/jwk/thumbprint.js` (safe): No malicious patterns detected; the code implements standard JWK thumbprint calculation without network, filesystem, process, or credential access.
- `dist/node/cjs/jwks/local.js` (safe): This is a legitimate JWKS (JSON Web Key Set) local key resolution module from the jose library with no malicious patterns detected.
- `dist/node/cjs/jwks/remote.js` (safe): No malicious patterns detected
- `dist/node/cjs/jws/compact/sign.js` (safe): No malicious patterns detected; the code is a straightforward JWS CompactSign wrapper implementing signing logic via an internal FlattenedSign dependency.
- `dist/node/cjs/jws/compact/verify.js` (safe): This JWS compact verification module contains no malicious patterns; it validates input and delegates to standard verification utilities.
- `dist/node/cjs/jws/flattened/sign.js` (safe): This is a legitimate JWS (JSON Web Signature) flattened signing implementation from the jose library with no malicious patterns detected.
- `dist/node/cjs/jws/flattened/verify.js` (safe): No malicious patterns detected; the code implements standard JWS flattened verification with input validation and no external calls or dynamic execution.
- `dist/node/cjs/jws/general/sign.js` (safe): No malicious patterns detected; the code is a standard JWS GeneralSign implementation with no exfiltration, obfuscation, process spawning, or suspicious activity.
- `dist/node/cjs/jws/general/verify.js` (safe): No malicious patterns detected
- `dist/node/cjs/jwt/decrypt.js` (safe): No malicious patterns detected; the code is a standard JWT decryption utility with claim validation and no external network, file system, or process manipulation.
- `dist/node/cjs/jwt/encrypt.js` (safe): The code is a legitimate JWT encryption implementation with no malicious patterns, external calls, or suspicious behavior.
- `dist/node/cjs/jwt/produce.js` (safe): No malicious patterns detected; this is a standard JWT claim builder implementation.
- `dist/node/cjs/jwt/sign.js` (safe): No malicious patterns detected; the code is a standard JWT signing implementation using the jose library with no data exfiltration, obfuscation, or suspicious behavior.
- `dist/node/cjs/jwt/unsecured.js` (safe): No malicious patterns detected; the code is a legitimate implementation of unsecured JSON Web Tokens (JWT with alg=none).
- `dist/node/cjs/jwt/verify.js` (safe): No malicious patterns detected in the JWT verification code.
- `dist/node/cjs/key/export.js` (safe): No malicious patterns detected
- `dist/node/cjs/key/generate_key_pair.js` (safe): The file is a thin, transparent wrapper that delegates key pair generation to an internal runtime module with no malicious patterns.
- `dist/node/cjs/key/generate_secret.js` (safe): No malicious patterns detected; the file is a thin, static wrapper that re-exports the generateSecret function from an internal runtime module.
- `dist/node/cjs/key/import.js` (safe): No malicious patterns detected
- `dist/node/cjs/lib/aesgcmkw.js` (safe): This is a standard AES-GCM key wrapping/unwrapping implementation with no malicious patterns detected.
- `dist/node/cjs/lib/buffer_utils.js` (safe): No malicious patterns detected; the file contains only cryptographic utility functions for buffer concatenation and key derivation.
- `dist/node/cjs/lib/cek.js` (safe): No malicious patterns detected; the code is a benign cryptographic utility for JWE algorithm bit lengths.
- `dist/node/cjs/lib/check_iv_length.js` (safe): No malicious patterns detected; the code is a simple initialization vector length validation utility.
- `dist/node/cjs/lib/check_key_type.js` (safe): The file contains only input validation logic for cryptographic key types and shows no malicious patterns, network activity, or dynamic code execution.
- `dist/node/cjs/lib/check_p2s.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/node/cjs/lib/crypto_key.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/node/cjs/lib/decrypt_key_management.js` (safe): No malicious patterns detected; the code implements standard JWE key management decryption routines without exfiltration, obfuscation, or suspicious behavior.
- `dist/node/cjs/lib/encrypt_key_management.js` (safe): No malicious patterns detected; the code is a standard JWE key management implementation using local cryptographic operations and no external network, filesystem, or process access.
- `dist/node/cjs/lib/epoch.js` (safe): No malicious patterns detected
- `dist/node/cjs/lib/invalid_key_input.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/node/cjs/lib/is_disjoint.js` (safe): No malicious patterns detected; the file contains a pure utility function that checks whether the keys of the provided header objects are disjoint, with no network, filesystem, process, or dynamic code execution activity.
- `dist/node/cjs/lib/is_object.js` (safe): No malicious patterns detected
- `dist/node/cjs/lib/iv.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/node/cjs/lib/jwt_claims_set.js` (safe): This is a standard JWT claims validation module with no malicious patterns; it only parses and validates claims without network, filesystem, or process operations.
- `dist/node/cjs/lib/secs.js` (safe): No malicious patterns detected
- `dist/node/cjs/lib/validate_algorithms.js` (safe): The file only contains a small pure validation helper that checks an option is an array of strings and converts it to a Set, with no network, filesystem, environment, process, or dynamic execution activity.
- `dist/node/cjs/lib/validate_crit.js` (safe): This JOSE critical header validation function contains no malicious patterns, external calls, or suspicious behavior; it is a standard security validation routine.
- `dist/node/cjs/runtime/aeskw.js` (safe): No malicious patterns detected; the code is a legitimate AES Key Wrap/Unwrap implementation using Node.js crypto APIs.
- `dist/node/cjs/runtime/asn1.js` (safe): No malicious patterns detected; the code is a standard cryptographic key format conversion utility using Node.js built-in crypto module.
- `dist/node/cjs/runtime/asn1_sequence_decoder.js` (safe): The file is a minimal ASN.1 DER sequence decoder with no network, filesystem, process, or dynamic execution behavior; no malicious patterns detected.
- `dist/node/cjs/runtime/asn1_sequence_encoder.js` (safe): No malicious patterns detected; the code is a straightforward ASN.1 DER encoder with no exfiltration, credential harvesting, dynamic execution, or suspicious behavior.
- `dist/node/cjs/runtime/base64url.js` (safe): No malicious patterns detected
- `dist/node/cjs/runtime/cbc_tag.js` (safe): No malicious patterns detected; the file is a straightforward CBC-MAC/HMAC tag computation using Node.js crypto primitives with no network, filesystem, process, or obfuscation activity.
- `dist/node/cjs/runtime/check_cek_length.js` (safe): The code performs only JWE Content Encryption Key length validation using standard library functions, with no malicious patterns detected.
- `dist/node/cjs/runtime/check_modulus_length.js` (safe): No malicious patterns detected; the file implements standard RSA modulus length validation for a JOSE/JWT library.
- `dist/node/cjs/runtime/ciphers.js` (safe): No malicious patterns detected
- `dist/node/cjs/runtime/decrypt.js` (safe): No malicious patterns detected; the code is a legitimate JWE decryption implementation for CBC and GCM modes with no exfiltration, obfuscation, or credential harvesting.
- `dist/node/cjs/runtime/digest.js` (safe): No malicious patterns detected
- `dist/node/cjs/runtime/dsa_digest.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/node/cjs/runtime/ecdhes.js` (safe): No malicious patterns detected
- `dist/node/cjs/runtime/encrypt.js` (safe): No malicious patterns detected; the code is a standard JWE encryption implementation using Node.js crypto APIs.
- `dist/node/cjs/runtime/fetch_jwks.js` (safe): The code is a standard JWKS fetcher with no malicious patterns; it only makes HTTP/HTTPS requests to a provided URL and parses JSON.
- `dist/node/cjs/runtime/flags.js` (safe): No malicious patterns detected; the file only inspects Node.js version numbers to set feature flags.
- `dist/node/cjs/runtime/generate.js` (safe): No malicious patterns detected; the code is a legitimate cryptographic key generation utility using Node.js crypto module.
- `dist/node/cjs/runtime/get_named_curve.js` (safe): No malicious patterns detected; the code performs standard cryptographic key curve identification for JOSE/JWK operations using Node.js crypto APIs.
- `dist/node/cjs/runtime/get_sign_verify_key.js` (safe): No malicious patterns detected
- `dist/node/cjs/runtime/hmac_digest.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/node/cjs/runtime/is_key_like.js` (safe): No malicious patterns detected
- `dist/node/cjs/runtime/is_key_object.js` (safe): No malicious patterns detected; the code only provides a safe feature-detection wrapper for checking KeyObject instances.
- `dist/node/cjs/runtime/jwk_to_key.js` (safe): No malicious patterns detected; the code is a legitimate JWK to crypto key conversion utility using Node.js crypto APIs.
- `dist/node/cjs/runtime/key_to_jwk.js` (safe): No malicious patterns detected; the code performs standard JWK conversion for cryptographic keys using Node.js crypto APIs without external calls, credential harvesting, or dynamic code execution.
- `dist/node/cjs/runtime/node_key.js` (safe): No malicious patterns detected
- `dist/node/cjs/runtime/pbes2kw.js` (safe): No malicious patterns detected; this is a standard PBES2 key wrapping implementation using Node.js crypto primitives.
- `dist/node/cjs/runtime/random.js` (safe): No malicious patterns detected; the file simply re-exports Node.js crypto.randomFillSync for cryptographic randomness.
- `dist/node/cjs/runtime/rsaes.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/node/cjs/runtime/runtime.js` (safe): No malicious patterns detected
- `dist/node/cjs/runtime/sign.js` (safe): No malicious patterns detected
- `dist/node/cjs/runtime/timing_safe_equal.js` (safe): No malicious patterns detected
- `dist/node/cjs/runtime/verify.js` (safe): No malicious patterns detected; the code is a standard JWT signature verification utility using Node.js crypto primitives.
- `dist/node/cjs/runtime/webcrypto.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/node/cjs/runtime/zlib.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/node/cjs/util/base64url.js` (safe): No malicious patterns detected
- `dist/node/cjs/util/decode_jwt.js` (safe): No malicious patterns detected; the code is a standard JWT payload decoder with no external communication, credential access, dynamic execution, or process spawning.
- `dist/node/cjs/util/decode_protected_header.js` (safe): No malicious patterns detected
- `dist/node/cjs/util/errors.js` (safe): No malicious patterns detected; the file only defines JOSE/JWT error classes and performs no I/O, network, process, or dynamic code execution.
- `dist/node/cjs/util/runtime.js` (safe): This file is a simple re-export shim that requires the runtime module and re-exports its default; no malicious patterns, dynamic code execution, network activity, or filesystem access are present.
- `dist/node/esm/index.js` (safe): This is a standard re-export barrel file for the jose library exposing JOSE/JWT cryptographic APIs; no malicious patterns, dynamic code execution, network activity, or install-time behavior are present.
- `dist/node/esm/jwe/compact/decrypt.js` (safe): No malicious patterns detected
- `dist/node/esm/jwe/compact/encrypt.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/node/esm/jwe/flattened/decrypt.js` (safe): No malicious patterns detected; the code is a standard JWE decryption implementation with proper input validation and no exfiltration, credential harvesting, or dynamic code execution.
- `dist/node/esm/jwe/flattened/encrypt.js` (safe): This is a standard JWE (JSON Web Encryption) implementation from the jose library; no malicious patterns, data exfiltration, credential harvesting, obfuscation, or process spawning were detected.
- `dist/node/esm/jwe/general/decrypt.js` (safe): No malicious patterns detected; the code is a standard JWE general decrypt routine with proper input validation and no exfiltration, obfuscation, or process spawning.
- `dist/node/esm/jwe/general/encrypt.js` (safe): No malicious patterns detected; this is a legitimate JWE General JSON encryption implementation from the jose library.
- `dist/node/esm/jwk/embedded.js` (safe): No malicious patterns detected
- `dist/node/esm/jwk/thumbprint.js` (safe): No malicious patterns detected
- `dist/node/esm/jwks/local.js` (safe): No malicious patterns detected
- `dist/node/esm/jwks/remote.js` (safe): No malicious patterns detected; the code is a standard JWKS remote key set implementation for JOSE/JWT verification with expected network fetching and caching behavior.
- `dist/node/esm/jws/compact/sign.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/node/esm/jws/compact/verify.js` (safe): No malicious patterns detected; the code is a standard JWS compact verification implementation.
- `dist/node/esm/jws/flattened/sign.js` (safe): This is a legitimate JWS signing implementation from the jose library with no malicious patterns detected.
- `dist/node/esm/jws/flattened/verify.js` (safe): No malicious patterns detected; the code implements JWS flattened signature verification using standard WebCrypto-style primitives and performs appropriate input validation without any exfiltration, obfuscation, or suspicious behavior.
- `dist/node/esm/jws/general/sign.js` (safe): No malicious patterns detected; this file implements JWS General Serialization using only in-package cryptographic signing logic and standard error handling.
- `dist/node/esm/jws/general/verify.js` (safe): No malicious patterns detected
- `dist/node/esm/jwt/decrypt.js` (safe): This JWT decryption module contains only legitimate cryptographic verification logic with no malicious patterns detected.
- `dist/node/esm/jwt/encrypt.js` (safe): No malicious patterns detected; the code is a straightforward JWT encryption utility with standard header and key management methods.
- `dist/node/esm/jwt/produce.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/node/esm/jwt/sign.js` (safe): No malicious patterns detected
- `dist/node/esm/jwt/unsecured.js` (safe): No malicious patterns detected
- `dist/node/esm/jwt/verify.js` (safe): No malicious patterns detected
- `dist/node/esm/key/export.js` (safe): No malicious patterns detected; the file only re-exports key format conversion functions without any exfiltration, obfuscation, or execution of external code.
- `dist/node/esm/key/generate_key_pair.js` (safe): The file is a simple wrapper that re-exports a key generation function with no suspicious behavior, network access, file system manipulation, or dynamic code execution.
- `dist/node/esm/key/generate_secret.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/node/esm/key/import.js` (safe): No malicious patterns detected; the code is a standard JOSE key import module performing input validation and cryptographic key conversion without network, filesystem, or dynamic execution behavior.
- `dist/node/esm/lib/buffer_utils.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/node/esm/lib/cek.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/node/esm/lib/check_iv_length.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/node/esm/lib/check_key_type.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/node/esm/lib/check_p2s.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/node/esm/lib/crypto_key.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/node/esm/lib/decrypt_key_management.js` (safe): The code implements JWE key management decryption for various algorithms with proper validation and no malicious patterns detected.
- `dist/node/esm/lib/encrypt_key_management.js` (safe): No malicious patterns detected; the code implements standard JWE key management algorithms without data exfiltration, credential harvesting, obfuscation, or suspicious network/process activity.

## Version ranges

None of the 2 scanned versions of jose are flagged high or critical. The latest scanned version, 6.2.12, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 6.2.1 – 6.2.12 (`>=6.2.1 <=6.2.12`): not scanned
- 6.1.3 (`6.1.3`): clean
- 5.10.0 (`5.10.0`): not scanned
- 4.15.9 (`4.15.9`): medium (Insecure JWT implementation (algorithm: none) +4 more)

## Scanned versions

- [6.1.3](https://security.togoder.click/npm/jose@6.1.3): safe, 2026-10-04T16:33:49.000Z
- [4.15.9](https://security.togoder.click/npm/jose@4.15.9): medium, 2026-10-06T14:17:14.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
