SOPlanning is vulnerable to Predictable Generation of...
High severity
Unreviewed
Published
Nov 20, 2025
to the GitHub Advisory Database
•
Updated Nov 24, 2025
Description
Published by the National Vulnerability Database
Nov 20, 2025
Published to the GitHub Advisory Database
Nov 20, 2025
Last updated
Nov 24, 2025
SOPlanning is vulnerable to Predictable Generation of Password Recovery Token. Due to weak mechanism of generating recovery tokens, a malicious attacker is able to brute-force all possible values and takeover any account in reasonable amount of time.
This issue was fixed in version 1.55.
References