@strapi/admin is vulnerable to Insufficient Session Expiration
68
Medium Risk
The @strapi/admin password-reset flow issues reset tokens that never expire and are not checked for age when a password reset is completed. A reset token leaked through email interception, log exposure, or a compromised inbox therefore stays valid indefinitely, allowing an attacker who obtains it to take over the admin account. The fix persists a resetPasswordTokenExpiresAt expiry (default one hour, configurable), rejects expired or legacy expiry-less tokens, and clears the stale token after use.
You are affected if you are using a version that falls within the vulnerable range and you use the admin panel forgot-password / reset-password flow.
@strapi/admin is vulnerable to Insufficient Session Expiration in versions 0.0.1 - 5.50.2.
Upgrade the @strapi/admin library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant