Flarum before 1.8.16 contains a password reset token...
Critical severity
Unreviewed
Published
Aug 5, 2026
to the GitHub Advisory Database
•
Updated Aug 5, 2026
Description
Published by the National Vulnerability Database
Aug 5, 2026
Published to the GitHub Advisory Database
Aug 5, 2026
Last updated
Aug 5, 2026
Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers to reuse expired password reset tokens by submitting them directly to the reset processing endpoint. The SavePasswordController::handle() method calls PasswordToken::findOrFail() without performing any expiry validation, allowing attackers to bypass the 24-hour token lifetime enforced only during form rendering and change any account's password to gain an authenticated session.
References