TROYANOSYVIRUS
Volver a CVEs

CVE-2026-1163

N/A

Descripcion

An insufficient session expiration vulnerability exists in the latest version of parisneo/lollms. The application fails to invalidate active sessions after a password reset, allowing an attacker to continue using an old session token. This issue arises due to the absence of logic to reject requests after a period of inactivity and the excessively long default session duration of 31 days. The vulnerability enables an attacker to maintain persistent access to a compromised account, even after the victim resets their password.

Detalles CVE

Puntuacion CVSS v3.1N/A
Publicado4/8/2026
Ultima modificacion4/8/2026
Fuentenvd
Avistamientos honeypot0

Debilidades (CWE)

CWE-613

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.