CVE-2025-64526: Strapi has a rate limit bypass on users-permissions plugin via attacker-controlled email keying
- CVE: CVE-2025-64526
- CVSS v3.1 Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N(6.9 — Medium) - Affected Versions:
@strapi/plugin-users-permissions<=5.44.0 - How to Patch: Immediately update your Strapi to >=5.45.0
References
Code Behaviors & Features
Detect and mitigate CVE-2025-64526 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →