CVE-2025-24365: vaultwarden allows escalation of privilege via variable confusion in OrgHeaders trait
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwardenrs. Attacker can obtain owner rights of other organization. Hacker should know the ID of victim organization (in real case the user can be a part of the organization as an unprivileged user) and be the owner/admin of other organization (by default you can create your own organization) in order to attack. This vulnerability is fixed in 1.33.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24365?
CVE-2025-24365 is classified as a high severity vulnerability due to the potential for an attacker to gain owner rights of another organization.
How do I fix CVE-2025-24365?
To fix CVE-2025-24365, upgrade to Vaultwarden version 1.33.0 or later.
Who is affected by CVE-2025-24365?
CVE-2025-24365 affects users running Vaultwarden versions prior to 1.33.0.
What are the potential impacts of CVE-2025-24365?
The potential impact of CVE-2025-24365 includes unauthorized access and control over organization resources.
Is CVE-2025-24365 a known exploit?
Yes, there are known exploitation scenarios for CVE-2025-24365 that allow attackers to hijack organizations.