Executive brief
The vulnerability-lookup web application's password reset feature contains two distinct security flaws in its user account recovery endpoint. First, a race condition allows attackers who possess a valid recovery token to exploit concurrent requests and set the target account's password to a value of their choosing, potentially overwriting a legitimate user's password change. Second, the same endpoint fails to validate password strength, allowing recovery tokens to set weak or empty passwords that bypass intended security constraints.
Technical details
A time-of-check-to-time-of-use (TOCTOU) race condition exists in the token consumption logic: the endpoint verifies the recovery token's nonce against the stored digest and then clears it in separate database transactions, allowing two concurrent requests with the same valid token to both pass verification before either commits, letting both set passwords. A secondary defect in the confirm_account view performs only manual field equality comparison and never invokes the form validator, bypassing minimum-length and complexity checks. The vulnerabilities are in website/models/user.py and website/web/views/user.py; the endpoint is /user/confirm_account/<token>. An attacker must possess a valid single-use recovery token, but no authentication is required to exploit either flaw.
Affected products
- vulnerability-lookup vulnerability-lookup unspecified
Timeline
- 2026-09-27: disclosed: CVE-2026-101041 published on NVD
- 2026-09-26: patched: Race condition fix in commit 5462bab62d76df852619e01eb67da36c023c8c40
- 2026-09-26: patched: Validation and token hardening in commit ad6f22882975516adf193a1a920aaa54025c71d4