CVE-2025-24365
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker can obtain owner rights of other organization. Hacker should know the ID of victim organization (in real case the user can be a part of the organization as an unprivileged user) and be the owner/admin of other organization (by default you can create your own organization) in order to attack. This vulnerability is fixed in 1.33.0.
- Affected products
- Alt Linux, Vaultwarden
- Dani-garcia Vaultwarden
- < 1.33.0
- Fix
- Available
- CVSS 3.1
- 8.1 HIGH
- EPSS
- 0.7% (48th percentile)
- Weakness
- CWE-284
- NVD status
- Analyzed
- Published
- 2025-01-27
CVE-2025-24365 at NVD
No indexed exploits for CVE-2025-24365 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-24365 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.