CVE-2025-3930
Last modified
CVE-2025-3930 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. Strapi uses JSON Web Tokens (JWT) for authentication. After logout or account deactivation, the JWT is not invalidated, which allows an attacker who has stolen or intercepted the token to freely reuse it until its expiration date (which is set to 30 days by default, but can be changed). EPSS estimates a 0.64% chance of exploitation in the next 30 days.
Description
Strapi uses JSON Web Tokens (JWT) for authentication. After logout or account deactivation, the JWT is not invalidated, which allows an attacker who has stolen or intercepted the token to freely reuse it until its expiration date (which is set to 30 days by default, but can be changed). The existence of /admin/renew-token endpoint allows anyone to renew near-expiration tokens indefinitely, further increasing the impact of this attack. This issue has been fixed in version 5.24.1.
Metrics
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-3930?
How severe is CVE-2025-3930?
How do I fix CVE-2025-3930?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-39246There is an Unquoted Service Path Vulnerability in some HikC…5.3
- CVE-2025-39247There is an Access Control Vulnerability in some HikCentral …8.6
- CVE-2025-3925BrightSign players running BrightSign OS series 4 prior to v…8.5
- CVE-2025-3927Digigram's PYKO-OUT audio-over-IP (AoIP) web-server does not…9.8
- CVE-2025-3928Commvault Web Server has an unspecified vulnerability that c…8.8
- CVE-2025-3929An XSS issue was discovered in MDaemon Email Server version …6.1
- CVE-2025-3931A flaw was found in Yggdrasil, which acts as a system broker…7.8
- CVE-2025-3932It was possible to craft an email that showed a tracking lin…6.5
- CVE-2025-3933A Regular Expression Denial of Service (ReDoS) vulnerability…5.3
- CVE-2025-39348Deserialization of Untrusted Data vulnerability in ThemeGood…9.8
- CVE-2025-39349Deserialization of Untrusted Data vulnerability in Potenzagl…9.8
- CVE-2025-3935ScreenConnect versions 25.2.3 and earlier versions may be su…7.2
Are you affected by CVE-2025-3930?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
