Weak Access Control in CryptPad Collaboration Suite
CVE-2025-49591

7.4HIGH

Key Information:

Vendor

Cryptpad

Status
Vendor
CVE Published:
18 June 2025

What is CVE-2025-49591?

Prior to version 2025.3.0, CryptPad, a collaborative suite, featured a critical weakness in its implementation of Two-Factor Authentication (2FA). This vulnerability allowed attackers to bypass 2FA enforcement simply by manipulating the path of the URL, which posed significant risks to user accounts. If an attacker successfully compromised a user's credentials, they could gain unauthorized access irrespective of the 2FA setup. The issue stemmed from inadequate validation of URL parameters, which did not enforce the necessary 2FA requirements if the path length restriction was not met. This flaw has been addressed in the latest release, 2025.3.0.

Affected Version(s)

cryptpad < 2025.3.0

References

CVSS V4

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-49591 : Weak Access Control in CryptPad Collaboration Suite