Weak Access Control in CryptPad Collaboration Suite
CVE-2025-49591
7.4HIGH
What is CVE-2025-49591?
Prior to version 2025.3.0, CryptPad, a collaborative suite, featured a critical weakness in its implementation of Two-Factor Authentication (2FA). This vulnerability allowed attackers to bypass 2FA enforcement simply by manipulating the path of the URL, which posed significant risks to user accounts. If an attacker successfully compromised a user's credentials, they could gain unauthorized access irrespective of the 2FA setup. The issue stemmed from inadequate validation of URL parameters, which did not enforce the necessary 2FA requirements if the path length restriction was not met. This flaw has been addressed in the latest release, 2025.3.0.
Affected Version(s)
cryptpad < 2025.3.0