GHSA-vc8q-vv59-f54cMediumCVSS 5.9

Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to...

Published
August 20, 2022
Last Modified
July 5, 2026

🔗 CVE IDs covered (1)

📋 Description

Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-middle attack via a crafted GET request.

🔗 References (5)