strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions/controllers/Auth.js.
AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence78%
Public exploitation · VTP factUNKNOWN
Assessment
Strapi releases before 3.0.0-beta.17.5 mishandle password resets in the admin and users-permissions authentication controllers. The 9.8 CVSS indicates unauthenticated remote compromise potential, although the supplied description does not detail the exploitation sequence.
Why it matters
A password-reset weakness can undermine account authentication and associated data or administrative controls.
EPSS is 0.97639 (99.898th percentile), which is predictive context only.
Evidence
1 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.
Uncertainties
The precise reset manipulation and required account state are not provided.
No KEV entry, exploit evidence, supporting source text, or first-party observation is supplied.
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
Next watchpoint
Identification of Strapi releases earlier than 3.0.0-beta.17.5.
Evidence confidence0%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
EPSS is 0.98; this is predictive context, not exploitation evidence.
02
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
02
Material change ledger
What changed
No material changes are recorded for this subject.
03
Claim provenance
Evidence and source independence
0publications detected
0underlying evidence chains
0 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.