Intel

AIKIDO-2025-10194

synapse is vulnerable to Authentication Bypass

Authentication Bypass Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Mar 31, 2025

22

Low Risk

This Affects:

Pythonsynapse
2.177.0 - 2.203.0
Fixed in 2.204.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are affected by a vulnerability where locked users could still access authenticated HTTP endpoints using an existing session cookie, bypassing account lock restrictions. User lock status now properly invalidates active sessions across all endpoints. An attacker could exploit this by retaining a valid session cookie after account lockout, leading to unauthorized access to authenticated endpoints.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

synapse is vulnerable to Authentication Bypass in versions 2.177.0 - 2.203.0.

How to fix this

Upgrade the synapse library to the patch version.