A critical security vulnerability, tracked as CVE-2025-59934, was discovered in Formbricks, an open-source alternative to Qualtrics. The flaw arises from the absence of proper JWT (JSON Web Token) signature verification in the application’s authentication and password reset mechanisms. Specifically, the token validation routine in Formbricks prior to version 4.0.1 only decodes JWTs without verifying their signatures, expiration, issuer, or audience. This oversight allows attackers to craft arbitrary JWTs with an 'alg: none' header, bypassing signature checks entirely. If an attacker is able to obtain a victim’s user ID, they can generate a forged JWT and use it to authenticate as the victim or reset their password without authorization. Both the email verification token login path and the password reset server action are affected by this vulnerability, as they share the same flawed validator. The vulnerability is remotely exploitable, significantly increasing the risk to organizations using affected versions of Formbricks. The issue has been assigned a CVSS 3.1 score of 9.4, indicating its critical severity. Security researchers and advisories have confirmed that the vulnerability can be exploited without any prior authentication, making it a prime target for attackers. The flaw was addressed and patched in Formbricks version 4.0.1, and users are strongly advised to upgrade immediately to mitigate the risk. The vulnerability was publicly disclosed on September 26, 2025, and quickly gained attention due to its potential impact on user accounts and sensitive data. Exploitation of this flaw could lead to unauthorized access, account takeover, and potential data breaches. The vulnerability affects all versions of Formbricks prior to 4.0.1, and there is no indication that earlier versions perform any additional checks to mitigate the risk. The security community has emphasized the importance of proper JWT signature verification as a fundamental security practice. Organizations using Formbricks should review their authentication logs for signs of suspicious activity and reset credentials as a precaution. The vulnerability highlights the dangers of improper implementation of authentication protocols in open-source software. Security advisories have been issued to raise awareness and provide guidance on remediation steps. The incident underscores the need for regular security reviews and prompt patching of critical vulnerabilities in widely used applications.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
A critical vulnerability, CVE-2025-59934, was publicly disclosed affecting Formbricks. The flaw involves missing JWT signature verification, which can allow forged tokens and unauthorized password resets.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.