Junglewise Threat Intelligence

CVE-2025-3930: Strapi insufficient session expiration in JWT authentication

CVE-2025-3930 · Severity: medium · CVSS 4 · Published 2025-10-16

Technologies: @strapi/strapi (npm). Vendors: npm, Strapi.

Executive brief

Strapi is an open-source headless CMS platform used to build content management systems and APIs. The platform uses JWT tokens for user authentication, but these tokens are not invalidated when a user logs out or their account is deactivated. An attacker who obtains a token can use it for up to 30 days (or longer if renewed), potentially gaining unauthorized access to content and administrative functions. This is particularly dangerous because there is a publicly accessible token renewal endpoint that allows indefinite token lifetime extension.

Technical details

Strapi uses JSON Web Tokens (JWT) for authentication but fails to invalidate tokens upon user logout or account deactivation (CWE-613: Insufficient Session Expiration). An attacker who steals or intercepts a JWT token can reuse it for authentication until the token naturally expires—by default 30 days, but configurable. The vulnerability is exacerbated by the presence of an unauthenticated `/admin/renew-token` endpoint that allows attackers to renew expiring tokens indefinitely, extending their window of unauthorized access. An attacker with a stolen token gains access to the same resources and administrative functions as the legitimate user. The vulnerability affects all versions prior to 5.24.1, which includes a fix for this issue.

Affected products

  • Strapi Strapi All versions prior to 5.24.1

Timeline

  • 2025-10-16: disclosed
  • 2025-10-16: patched: Fixed in version 5.24.1

References

Related threats