GHSA-4r8w-3jww-m2rp · Severity: medium · Ecosystem: npm — Strapi is vulnerable to Insufficient Session Expiration
Strapi uses JSON Web Tokens (JWT) for authentication. After logout or account deactivation, the JWT is not invalidated, which allows an attacker who has stolen or intercepted the token to freely reuse it until its expiration date (which is set to 30 days by default, but can be changed). The existence of /admin/renew-token endpoint allows anyone to renew near-expiration tokens indefinitely, further increasing the impact of this attack. This issue has been fixed in version 5.24.1.
Conclusion & alert: CVE-2025-3930 is rated Moderate Risk (41.7/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.64%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.10% | 0.64% | +0.55% |
| 2 | 2025-11-27 | 0.16% | 0.10% | -0.07% |
| 3 | 2025-11-10 | — | 0.16% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.3 | 4.0 | MEDIUM |
|
— | — | [email protected] |
GHSA-4r8w-3jww-m2rp · Severity: medium · Ecosystem: npm — Strapi is vulnerable to Insufficient Session Expiration
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||