PT-2025-39695 · Unknown · Formbricks

CVE-2025-59934

·

Publicado

2025-09-26

·

Atualizado

2025-11-02

CVSS v2.0

9.7

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:P
Name of the Vulnerable Software and Affected Versions Formbricks versions prior to 4.0.1
Description Formbricks, an open source qualtrics alternative, is affected by a missing JWT signature verification issue. The token validation routine only decodes JWTs without verifying their signatures, expiration, issuer, or audience. This impacts the email verification token login path and the password reset server action. An attacker who obtains a victim’s user.id can craft a JWT with an 'alg: "none"' header to authenticate and reset the victim’s password. Approximately 6.3K+ services are found on the internet yearly.
Recommendations Upgrade to version 4.0.1 or later to resolve this issue.

Exploit

Correção

Insufficient Verification of Data Authenticity

Improper Verification of Cryptographic Signature

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-02093
CVE-2025-59934
GHSA-7229-Q9PV-J6P4

Produtos afetados

Formbricks