Threat Advisory

Decidim Vulnerability May Gain Access to Export Content

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High


EXECUTIVE SUMMARY:

A vulnerability has been CVE-2025-65017 identified in the Decidim open-source platforms private data export functionality that could allow attackers to cause unauthorized exposure of private user details. The vulnerability stems from a defect in UUID generation that can lead to collisions during private export operations, potentially enabling an attacker to access or download another users private export file without proper authorization. The issue affects Decidim versions and has been addressed in version; organizations using affected releases are advised to update promptly to mitigate the risk of data leaks and protect sensitive information. The vulnerability has a CVSS score of 8.2.

 

RECOMMENDATION:

  • We strongly recommend you update Decidim to version 0.30.4 or 0.31.0 or later.

 

REFERENCES:

The following reports contain further technical details:

https://github.com/advisories/GHSA-3cx6-j9j4-54mp

crossmenu