HomeSecurityFormbricks: Vulnerability allows password reset without authorization

Formbricks: Vulnerability allows password reset without authorization

A critical security vulnerability has been discovered in Formbricks and could allow complete account takeover.

Formbricks vulnerability

Formbricks is an open-source experience management platform. The vulnerability, tracked as CVE-2025-59934 , affects all versions prior to 4.0.1. It results from improper token validation using jwt.decode() instead of jwt.verify(), allowing attackers to completely bypass authentication checks.

The vulnerability was discovered by security researcher mattinannt and has been classified as “critical” due to its potential for unauthorized access to user accounts.

See also: Hackers exploit Dynamic DNS providers for malicious purposes

Formbricks has released version 4.0.1 to address this security issue, but organizations using older versions remain at significant risk.

Formbricks: JWT Validation Vulnerability

The core vulnerability exists in the token validation routine located in /formbricks/apps/web/lib/jwt.ts. The problematic code implements a verifyToken function that simply decodes JWT tokens without performing basic security checks. This implementation fails to verify critical elements of the JWT, including digital signatures, token expiration, issuer validation, and audience verification.

The function uses jwt.decode() which simply parses the JWT structure without cryptographic validation, treating any properly formatted JWT as authentic regardless of its legitimacy.

See also: Notepad++: DLL Hijacking Vulnerability Allows Code Execution

Formbricks: Vulnerability allows password reset without authorization

It is worth noting that both the email verification token login path and functionality password reset rely on this flawed validator. When processing password reset requests, the system extracts the user ID from the unverified JWT payload and directly queries the database to update the user’s corresponding password. This bypass mechanism allows attackers, in possession of the victim’s user ID, to create malicious JWTs using the “alg”: “none” algorithm header, essentially creating unsigned tokens that pass verification.

The exploit requires minimal prerequisites – attackers only need to discover the target’s unique identifier, which follows the standard Formbricks format (e.g., cmfuc8pk60000vxfjud7bcl2w). The attack exploits the “none” algorithm specification in JWT headers, which indicates that no signature verification should be performed.

See also: Technical details of LummaStealer revealed through ML models

The proof-of-concept demonstrates token forgery using a Python script that constructs a malicious JWT. The attack sequence follows these steps: the attacker creates a JWT with header {“alg”: “none”, “typ”: “JWT”} and payload containing the victim’s user ID, constructs a password reset URL containing the forged token, and submits the form with a new password.

The server's verifyToken function accepts the unsigned token, extracts the user ID, and proceeds to update the password without performing signature verification. This attack path demonstrates a fundamental authentication bypass vulnerability, where the absence of cryptographic validation renders the entire JWT-based security model ineffective.

See also: Akira ransomware compromises MFA-protected SonicWall VPN accounts

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Formbricks: Vulnerability allows password reset without authorization

Protection

The vulnerability affects password reset functionality and email verification processes, potentially allowing widespread account compromise across Formbricks installations. Organizations using affected versions of Formbricks should immediately upgrade to version 4.0.1 or later and review authentication logs for suspicious password reset activity.

The update implements proper JWT signature verification using jwt.verify() instead of the vulnerable jwt.decode() method, ensuring that only cryptographically valid tokens can authenticate users and authorize sensitive operations such as password resets. A full-scale breach and account takeover can have far-reaching consequences for an organization. Security experts should act immediately.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS