GITHUB-ACTIONS · JULY 2026 · EARLY WARNING

Decidim JWT-backed Authentication Vulnerability: Early Warning

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-R3V7-5X4C-C69QSeverity: HIGH

An early warning has been issued regarding a vulnerability in Decidim where JWT-backed authentication can reportedly be replayed across different organizations, potentially allowing unauthorized access to sensitive information.

What happened

According to the advisory, it appears that a JSON Web Token (JWT) issued for one organization can be replayed successfully against another organization's API. This could allow an attacker to retrieve sensitive details from the targeted organization using the replayed JWT. The vulnerability is under investigation and the exact scope and impact are not yet fully understood.

Professional software engineers using Decidim are advised to assess their exposure by reviewing their use of JWT-backed authentication. As a precautionary measure, it is recommended to upgrade to the latest version of Decidim and disable JWT credentials on the system panel if immediate action is required. For more detailed information, consult the primary sources linked in the advisory.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If decidim is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats