Logic Bug Found in Burp Suite's Top JWT Editor Extension After 15-Hour Investigation

A security researcher discovered a silent logic flaw in the JWT Editor extension for Burp Suite, currently the platform's most popular BApp Store tool and a nominee for its 2026 Best Auth & Access Control award. The bug surfaced during a routine Web Security Academy lab on JWT algorithm confusion, where the researcher's forged tokens were consistently rejected despite following the correct steps exactly. After ruling out user error through multiple community walkthroughs and official documentation, a 15-hour root-cause investigation pointed to the extension itself silently contaminating HMAC keys. The flaw relates to how the extension handles the Base64-encoded public key used as an HMAC secret during RS256-to-HS256 algorithm confusion attacks. The researcher ultimately filed a GitHub issue against the extension, highlighting how tooling bugs can silently undermine security testing workflows.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in