Junglewise Threat Intelligence

CVE-2025-64526: Strapi users-permissions plugin rate limit bypass in auth routes

CVE-2025-64526 · Severity: medium · CVSS 5.3 · Published 2026-05-14

Technologies: Strapi Plugin-Users-Permissions, @strapi/plugin-users-permissions (npm), Strapi Users & Permissions Plugin. Vendors: Strapi, npm.

Executive brief

Strapi is an open-source content management system used to manage and deliver digital content. A security flaw in its user permissions plugin allows attackers to bypass rate limits on sensitive pages like login and password reset. This could enable malicious actors to perform high-volume automated attacks, such as guessing user passwords or reset codes, potentially leading to unauthorized account access.

Technical details

A rate-limit bypass exists in the Strapi users-permissions plugin due to improper rate-limit key generation. The middleware incorrectly incorporated an 'email' field from the request body into the rate-limit key even for routes where 'email' is not a valid or required field (such as /auth/local or /auth/reset-password). By providing a unique, arbitrary email value in each request, an unauthenticated attacker can generate a fresh rate-limit key, effectively neutralizing per-IP throttling. This enables large-scale credential stuffing and brute-force attacks against login and password reset endpoints. The vulnerability is addressed in version 5.45.0 by implementing an allow-list for routes that legitimately use the email field as an identifier.

Affected products

  • Strapi Strapi plugin-users-permissions < 5.45.0

Timeline

  • 2025-11-10: other: Vulnerability reported and fix initiated in PR #24818
  • 2026-05-06: patched: Version 5.45.0 released
  • 2026-05-14: advisory: NVD and GitHub Security Advisory published

References

Related threats