PT-2025-27554 · Sentry+1 · Sentry+1

Rakesh0X7

·

Published

2025-07-01

·

Updated

2026-01-22

·

CVE-2025-53099

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Sentry versions prior to 25.5.0
Description: The issue allows an attacker with a malicious OAuth application registered with Sentry to take advantage of a race condition and improper handling of authorization code within Sentry, maintaining persistence to a user's account. This can be achieved through specially timed requests and redirect flows, generating multiple authorization codes that can be used to exchange for access and refresh tokens, even after de-authorizing the particular application.
Recommendations: For self-hosted Sentry users, upgrade to version 25.5.0 or higher. For Sentry SaaS users, no action is required.

Exploit

Fix

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

BDU:2026-03562
CVE-2025-53099
GHSA-MGH8-H4XC-PFMJ

Affected Products

Red Os
Sentry