CVE-2026-33417

high

Description

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.2, password reset tokens in Wallos never expire. The password_resets table includes a created_at timestamp column, but the token validation logic never checks it. A password reset token remains valid indefinitely until it is used, allowing an attacker who intercepts a reset link at any point to use it days, weeks, or months later. This issue has been patched in version 4.7.2.

References

https://github.com/ellite/Wallos/security/advisories/GHSA-p3fv-m43r-3fhf

https://github.com/ellite/Wallos/commit/90bb6186ee4091590b6efdef824c85f2494ff2bb

Details

Source: Mitre, NVD

Published: 2026-03-24

Updated: 2026-03-26

Risk Information

CVSS v2

Base Score: 8.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:P/A:N

Severity: High

CVSS v3

Base Score: 7.1

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N

Severity: High

EPSS

EPSS: 0.0003