GHSA-4r8w-3jww-m2rp

Suggest an improvement
Source
https://github.com/advisories/GHSA-4r8w-3jww-m2rp
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-4r8w-3jww-m2rp/GHSA-4r8w-3jww-m2rp.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4r8w-3jww-m2rp
Aliases
Published
2025-10-16T12:30:23Z
Modified
2025-10-22T19:36:22Z
Severity
  • 6.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Strapi is vulnerable to Insufficient Session Expiration
Details

Strapi uses JSON Web Tokens (JWT) for authentication. After logout or account deactivation, the JWT is not invalidated, which allows an attacker who has stolen or intercepted the token to freely reuse it until its expiration date (which is set to 30 days by default, but can be changed). The existence of /admin/renew-token endpoint allows anyone to renew near-expiration tokens indefinitely, further increasing the impact of this attack. This issue has been fixed in version 5.24.1.

Database specific
{
    "cwe_ids":  [
        "CWE-613"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-10-16T21:21:44Z",
    "nvd_published_at":  "2025-10-16T11:15:29Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / @strapi/strapi

Package

Name
@strapi/strapi
View open source insights on deps.dev
Purl
pkg:npm/%40strapi/strapi

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.24.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-4r8w-3jww-m2rp/GHSA-4r8w-3jww-m2rp.json"