PT-2026-99549 · Unknown · Vulnerability-Lookup
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
vulnerability-lookup (affected versions not specified)
Description
The account recovery functionality contains a time-of-check-to-time-of-use (TOCTOU) race condition—a scenario where a system checks a condition and then uses the result, but the condition changes between the check and the use—during the consumption of single-use recovery tokens. This occurs because the system verifies the token nonce and clears it in separate database operations. Consequently, two concurrent HTTP requests using the same valid token can both pass verification, allowing an attacker with a valid token to overwrite a legitimate user's password. Additionally, the
/user/confirm account/<token> endpoint allows setting empty or trivially short passwords because the view handler performs a manual equality comparison between password fields without invoking the form's validation logic, bypassing complexity and length constraints. The issue resides in the User model (website/models/user.py) and the view layer (website/web/views/user.py).Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Race Condition
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vulnerability-Lookup