PT-2025-47368 · Wiki.Js · Wiki.Js

Published

2025-11-06

·

Updated

2025-11-19

·

CVE-2025-56643

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Wiki.js version 2.5.307
Description Wiki.js does not properly revoke or invalidate active JWT tokens when a user logs out. This allows previously issued tokens to remain valid and be reused to access the system, even after logout. The issue impacts session integrity and could allow unauthorized access if a token is compromised. The problem exists in the authentication resolver logic, affecting the GraphQL endpoint and the logout mechanism.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00043
CVE-2025-56643

Affected Products

Wiki.Js