CVE-2025-49591: CryptPad 2FA Bypass Vulnerability
CryptPad is a collaboration suite. Prior to version 2025.3.0, enforcement of Two-Factor Authentication (2FA) in CryptPad can be trivially bypassed, due to weak implementation of access controls. An attacker that compromises a user's credentials can gain access to the victim's account, even if the victim has 2FA set up. This is due to 2FA not being enforced if the path parameter is not 44 characters long, which can be bypassed by simply URL encoding a single character in the path. This issue has been patched in version 2025.3.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49591?
CVE-2025-49591 has a high severity rating due to the potential for unauthorized access to user accounts.
How do I fix CVE-2025-49591?
To fix CVE-2025-49591, upgrade CryptPad to version 2025.3.0 or later.
What type of vulnerability is CVE-2025-49591?
CVE-2025-49591 is an access control vulnerability related to Two-Factor Authentication (2FA) enforcement.
Who is affected by CVE-2025-49591?
CVE-2025-49591 affects all users of CryptPad prior to version 2025.3.0.
Can the Two-Factor Authentication be bypassed in CVE-2025-49591?
Yes, the weak implementation in CVE-2025-49591 allows an attacker to trivially bypass Two-Factor Authentication.