CVEFinder.io

CVE-2025-3930

๐Ÿ”ถ medium
๐Ÿ” Scan for this CVE
Summary

Strapi uses JSON Web Tokens (JWT) for authentication. After logout or account deactivation, the JWT is not invalidated, which allows an attacker who has stolen or intercepted the token to freely reuse it until its expiration date (which is set to 30 days by default, but can be changed). The existence of /admin/renew-tokenย endpoint allows anyone to renew near-expiration tokens indefinitely, further increasing the impact of this attack. This issue has been fixed in version 5.24.1.

CVSS Score
-
EPSS Score
0.1
Exploit Probability
Published Date
2025-10-16
First Seen: 2026-01-05
๐ŸŽฏ CISA SSVC Assessment Updated: Oct 16, 2025
๐Ÿ” Exploitation Status
None
No known exploits
โš™๏ธ Automatable
NO
Requires human interaction
๐Ÿ’ฅ Technical Impact
Partial
Limited system impact
๐Ÿ† Discovered By
Arkadiusz Marta
SSVC data provided by CISA
Last Modified 2025-10-22
CVSS Vector 4.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE IDs (Weakness Types)

๐Ÿ“ฆ Affected Products 1

๐Ÿ”— References 4

๐Ÿ”— Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2025-64526 ๐Ÿ”ถ medium 5.3 0.0 Strapi is an open source headless content management system. In Strapi versions prior to 5.45.0, the rate-limit middlewa... 2026-05-14
CVE-2026-22599 โš ๏ธ high 7.2 0.1 Strapi is an open source headless content management system. In versions on the 4.x branch prior to 4.26.1 and on the 5.... 2026-05-14
CVE-2026-22706 ๐Ÿ”ถ medium 6.5 0.0 Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, changing or resetting a... 2026-05-14
CVE-2026-22707 ๐Ÿ”ถ medium 5.4 0.0 Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, the Upload plugin's Con... 2026-05-14
CVE-2026-27886 โš ๏ธ high 7.5 0.1 Strapi is an open source headless content management system. Strapi versions starting in 4.0.0 and prior to 5.37.0 did n... 2026-05-14
CVE-2024-56143 โš ๏ธ high 8.2 0.0 Strapi is an open-source headless content management system. In versions from 5.0.0 to before 5.5.2, the lookup operator... 2025-10-16
These CVEs affect the same products