← Vulnerability feed

Vulnerability record · CVE-2023-48220 · published 20 February 2024

CVE-2023-48220: Decidim vulnerability

Decidim · Decidim

Decidim is a participatory democracy framework. Starting in version 0.4.rc3 and prior to version 2.0.9 of the `devise_invitable` gem, the invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. This issue creates vulnerable dependencies starting in version 0.0.1.alpha3 and prior to versions 0.26.9, 0.27.5, and 0.28.0 of the `decidim,` `decidim-admin`, and `decidim-system` gems. When using the password reset functionality, the `devise_invitable` gem always accepts the pending invitation if the user has been invited. The only check done is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the `invite_for` expiry period. Decidim sets this configuration to `2.weeks` so this configuration should be respected. The bug is in the `devise_invitable` gem and should be fixed there and the dependency should be upgraded in Decidim once the fix becomes available. `devise_invitable` to version `2.0.9` and above fix this issue. Versions 0.26.9, 0.27.5, and 0.28.0 of the `decidim,` `decidim-admin`, and `decidim-system` gems contain this fix. As a workaround, invitations can be cancelled directly from the database.

7.4 CVSS 3.1 High EPSS 0.79% · top 45.5% CWE-672 · CWE-672
7.4CVSS 3.1 base score
0.79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
18References
17 Jun 2026Last modified by NVD

Description

Decidim is a participatory democracy framework. Starting in version 0.4.rc3 and prior to version 2.0.9 of the `devise_invitable` gem, the invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. This issue creates vulnerable dependencies starting in version 0.0.1.alpha3 and prior to versions 0.26.9, 0.27.5, and 0.28.0 of the `decidim,` `decidim-admin`, and `decidim-system` gems. When using the password reset functionality, the `devise_invitable` gem always accepts the pending invitation if the user has been invited. The only check done is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the `invite_for` expiry period. Decidim sets this configuration to `2.weeks` so this configuration should be respected. The bug is in the `devise_invitable` gem and should be fixed there and the dependency should be upgraded in Decidim once the fix becomes available. `devise_invitable` to version `2.0.9` and above fix this issue. Versions 0.26.9, 0.27.5, and 0.28.0 of the `decidim,` `decidim-admin`, and `decidim-system` gems contain this fix. As a workaround, invitations can be cancelled directly from the database.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/decidim/decidim/blob/d2d390578050772d1bdb6d731395f1afc39dcbfc/decidim-core/config/initializers/devise Product
https://github.com/decidim/decidim/commit/073e60e2e4224dd81815a784002ebba30f2ebb34 Patch
https://github.com/decidim/decidim/commit/b12800717a689c295a9ea680a38ca9f823d2c454 Patch
https://github.com/decidim/decidim/releases/tag/v0.26.9 Release Notes
https://github.com/decidim/decidim/releases/tag/v0.27.5 Release Notes
https://github.com/decidim/decidim/releases/tag/v0.28.0 Release Notes
https://github.com/decidim/decidim/security/advisories/GHSA-w3q8-m492-4pwp MitigationPatchVendor Advisory
https://github.com/scambra/devise_invitable/blob/41f58970ff76fb64382a9b9ea1bd530f7c3adab2/lib/devise_invitable/models.rb Product
https://github.com/scambra/devise_invitable/commit/94d859c7de0829bf63f679ae5dd3cab2b866a098 Patch
https://github.com/decidim/decidim/blob/d2d390578050772d1bdb6d731395f1afc39dcbfc/decidim-core/config/initializers/devise Product
https://github.com/decidim/decidim/commit/073e60e2e4224dd81815a784002ebba30f2ebb34 Patch
https://github.com/decidim/decidim/commit/b12800717a689c295a9ea680a38ca9f823d2c454 Patch
https://github.com/decidim/decidim/releases/tag/v0.26.9 Release Notes
https://github.com/decidim/decidim/releases/tag/v0.27.5 Release Notes
https://github.com/decidim/decidim/releases/tag/v0.28.0 Release Notes
https://github.com/decidim/decidim/security/advisories/GHSA-w3q8-m492-4pwp MitigationPatchVendor Advisory
https://github.com/scambra/devise_invitable/blob/41f58970ff76fb64382a9b9ea1bd530f7c3adab2/lib/devise_invitable/models.rb Product
https://github.com/scambra/devise_invitable/commit/94d859c7de0829bf63f679ae5dd3cab2b866a098 Patch

Track CVE-2023-48220 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2026-23891Decidim cross-site scripting vulnerabilityDecidim is a participatory democracy framework. In versions below 0.30.5 and 0.31.0.rc1 through 0.31.0, a stored code execution vulnerability in the …EPSS 0.36%8.2CVE-2025-65017Decidim information exposure vulnerabilityDecidim is a participatory democracy framework. In versions from 0.30.0 to before 0.30.4 and from 0.31.0.rc1 to before 0.31.0, the private data expor…EPSS 0.28%7.5CVE-2023-34090Decidim information exposure vulnerabilityDecidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline p…EPSS 1.3%7.1CVE-2023-36465Decidim improper access control vulnerabilityDecidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline p…EPSS 0.54%6.5CVE-2026-40869Decidim vulnerabilityDecidim is a participatory democracy framework. Starting in version 0.19.0 and prior to versions 0.30.5 and 0.31.1, a vulnerability allows any regist…EPSS 0.31%6.1CVE-2023-34089Decidim cross-site scripting vulnerabilityDecidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline p…EPSS 0.74%6.1CVE-2023-32693Decidim cross-site scripting vulnerabilityDecidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline p…EPSS 0.82%5.7CVE-2023-47635Decidim server-side request forgery (ssrf) vulnerabilityDecidim is a participatory democracy framework. Starting in version 0.23.0 and prior to versions 0.27.5 and 0.28.0, the CSRF authenticity token check…EPSS 0.31%

Source: NIST National Vulnerability Database (record CVE-2023-48220), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.