PT-2025-23266 · Zitadel · Zitadel

Amit-Laish

·

Published

2025-05-28

·

Updated

2025-06-16

·

CVE-2025-48936

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zitadel versions prior to 2.70.12 Zitadel versions prior to 2.71.10 Zitadel versions prior to 3.2.2
Description Zitadel is open-source identity infrastructure software. A potential issue exists in the password reset mechanism, where ZITADEL utilizes the Forwarded or X-Forwarded-Host header from incoming requests to construct the URL for the password reset confirmation link. This link, containing a secret code, is then emailed to the user. If an attacker can manipulate these headers, they could cause ZITadel to generate a password reset link pointing to a malicious domain controlled by the attacker. If the user clicks this manipulated link in the email, the secret reset code embedded in the URL can be captured by the attacker. This captured code could then be used to reset the user's password and gain unauthorized access to their account. This specific attack vector is mitigated for accounts that have Multi-Factor Authentication (MFA) or Passwordless authentication enabled.
Recommendations For versions prior to 2.70.12, update to version 2.70.12 or later. For versions prior to 2.71.10, update to version 2.71.10 or later. For versions prior to 3.2.2, update to version 3.2.2 or later. As a temporary workaround, consider enabling Multi-Factor Authentication (MFA) or Passwordless authentication to mitigate the risk of exploitation.

Exploit

Fix

Open Redirect

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-48936
GHSA-93M4-MFPG-C3XF
GO-2025-3721

Affected Products

Zitadel