PT-2025-39695 · Unknown · Formbricks

Published

2025-09-26

·

Updated

2025-11-02

·

CVE-2025-59934

CVSS v2.0

9.7

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:P
Name of the Vulnerable Software and Affected Versions Formbricks versions prior to 4.0.1
Description Formbricks, an open source qualtrics alternative, is affected by a missing JWT signature verification issue. The token validation routine only decodes JWTs without verifying their signatures, expiration, issuer, or audience. This impacts the email verification token login path and the password reset server action. An attacker who obtains a victim’s user.id can craft a JWT with an 'alg: "none"' header to authenticate and reset the victim’s password. Approximately 6.3K+ services are found on the internet yearly.
Recommendations Upgrade to version 4.0.1 or later to resolve this issue.

Exploit

Fix

Insufficient Verification of Data Authenticity

Improper Verification of Cryptographic Signature

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2026-02093
CVE-2025-59934
GHSA-7229-Q9PV-J6P4

Affected Products

Formbricks