CVE-2025-59934Active Exploitation

MEDIUMCVSS 9.4 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Formbricks is an open source qualtrics alternative. Prior to version 4.0.1, Formbricks is missing JWT signature verification. This vulnerability stems from a token validation routine that only decodes JWTs (jwt.decode) without verifying their signatures. Both the email verification token login path and the password reset server action use the same validator, which does not check the token’s signature, expiration, issuer, or audience. If an attacker learns the victim’s actual user.id, they can craft an arbitrary JWT with an alg: "none" header and use it to authenticate and reset the victim’s password. This issue has been patched in version 4.0.1.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-345CWE-347

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-05: 2Active Exploitation · 2026-02-05: 1Patch / Workaround · 2026-02-05: 1Technical Details · 2026-02-05: 102-05
Signal classification2 categories
Active Exploitation
150.0%
Patch
150.0%
Full discourse2 posts
  • Jaco M.V.@jacomasvirtual
    Active Exploitation

    El culpable: un contenedor de Formbricks comprometido. CVE-2025-59934 permite acceso no autorizado y ejecución remota de código. Los atacantes instalaron un minero completo. Sin alertas visibles en logs normales.

    Post summary

    CVE-2025-59934 is being actively exploited; attackers deployed a full miner on compromised Formbricks containers, enabling unauthorized access and remote code execution without leaving obvious logs.

    1000035
    28 followersView on X
  • Jaco M.V.@jacomasvirtual
    Patch

    Un contenedor desactualizado me costó 29.5 TB y throttling del servidor. El parche para CVE-2025-59934 existía desde hace meses. No esperes a que te pase. ¿Cuándo fue la última vez que auditaste tus contenedores?

    Post summary

    The user highlights that a patch for CVE‑2025‑59934 has been available for months, emphasizing the importance of keeping containers up‑to‑date to avoid severe impacts.

    0000034
    28 followersView on X

Explore more