A critical security vulnerability has been discovered in Formbricks and could allow complete account takeover.

Formbricks is an open-source experience management platform. The vulnerability, tracked as CVE-2025-59934 , affects all versions prior to 4.0.1. It results from improper token validation using jwt.decode() instead of jwt.verify(), allowing attackers to completely bypass authentication checks.
The vulnerability was discovered by security researcher mattinannt and has been classified as “critical” due to its potential for unauthorized access to user accounts.
See also: Hackers exploit Dynamic DNS providers for malicious purposes
Formbricks has released version 4.0.1 to address this security issue, but organizations using older versions remain at significant risk.
Formbricks: JWT Validation Vulnerability
The core vulnerability exists in the token validation routine located in /formbricks/apps/web/lib/jwt.ts. The problematic code implements a verifyToken function that simply decodes JWT tokens without performing basic security checks. This implementation fails to verify critical elements of the JWT, including digital signatures, token expiration, issuer validation, and audience verification.
The function uses jwt.decode() which simply parses the JWT structure without cryptographic validation, treating any properly formatted JWT as authentic regardless of its legitimacy.
See also: Notepad++: DLL Hijacking Vulnerability Allows Code Execution

It is worth noting that both the email verification token login path and functionality password reset rely on this flawed validator. When processing password reset requests, the system extracts the user ID from the unverified JWT payload and directly queries the database to update the user’s corresponding password. This bypass mechanism allows attackers, in possession of the victim’s user ID, to create malicious JWTs using the “alg”: “none” algorithm header, essentially creating unsigned tokens that pass verification.
The exploit requires minimal prerequisites – attackers only need to discover the target’s unique identifier, which follows the standard Formbricks format (e.g., cmfuc8pk60000vxfjud7bcl2w). The attack exploits the “none” algorithm specification in JWT headers, which indicates that no signature verification should be performed.
See also: Technical details of LummaStealer revealed through ML models
The proof-of-concept demonstrates token forgery using a Python script that constructs a malicious JWT. The attack sequence follows these steps: the attacker creates a JWT with header {“alg”: “none”, “typ”: “JWT”} and payload containing the victim’s user ID, constructs a password reset URL containing the forged token, and submits the form with a new password.
The server's verifyToken function accepts the unsigned token, extracts the user ID, and proceeds to update the password without performing signature verification. This attack path demonstrates a fundamental authentication bypass vulnerability, where the absence of cryptographic validation renders the entire JWT-based security model ineffective.
See also: Akira ransomware compromises MFA-protected SonicWall VPN accounts
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Protection
The vulnerability affects password reset functionality and email verification processes, potentially allowing widespread account compromise across Formbricks installations. Organizations using affected versions of Formbricks should immediately upgrade to version 4.0.1 or later and review authentication logs for suspicious password reset activity.
The update implements proper JWT signature verification using jwt.verify() instead of the vulnerable jwt.decode() method, ensuring that only cryptographically valid tokens can authenticate users and authorize sensitive operations such as password resets. A full-scale breach and account takeover can have far-reaching consequences for an organization. Security experts should act immediately.
