ZITADEL, an identity and access management platform, has been found to contain critical vulnerabilities, including CVE-2025-67494 (CVSS 9.3) and CVE-2025-67495, that expose users to significant security risks. The flaws allow for server-side request forgery (SSRF), internal breaches, and account hijacking through DOM-based cross-site scripting (XSS) in the Zitadel V2 login interface. Successful exploitation could enable attackers to compromise user accounts and potentially gain unauthorized access to internal resources.
Security advisories highlight the severity of these issues, urging organizations using ZITADEL to apply patches and mitigations immediately. The vulnerabilities underscore the importance of robust input validation and prompt security updates in identity management solutions to prevent exploitation and protect sensitive authentication infrastructure.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A vulnerability report disclosed CVE-2025-67494 in ZITADEL, describing critical risks including SSRF that could lead to internal breach and XSS that could enable account hijacking. The report assigned the issue a CVSS score of 9.3.
A high-severity vulnerability affecting the ZITADEL V2 login flow was publicly reported as CVE-2025-67495. The DOM-based XSS issue was described as enabling account takeover and assigned a CVSS v3.1 score of 8.0.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.