CVE 8.2 HIGH

Decidim’s private data exports can lead to data leaks_CVE-2025-65017

8.2 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

Description

Decidim is a participatory democracy framework. In versions from 0.30.0 to before 0.30.4 and from 0.31.0.rc1 to before 0.31.0, the private data exports can lead to data leaks in case the UUID generation, causing collisions for the generated UUIDs. This issue has been patched in versions 0.30.4 and 0.31.0.

Basic Information

ID CVE-2025-65017
Source GitHub_M
Published Feb 3, 2026 at 15:05

Affected Product

Vendor decidim
Product decidim
Version >= 0.30.0, < 0.30.4
Affected Versions decidim decidim >= 0.30.0, < 0.30.4
decidim decidim >= 0.31.0.r1, < 0.31.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.