Password Reset Token Mismanagement in CISA Thorium
CVE-2025-35433
What is CVE-2025-35433?
The CISA Thorium application contains a vulnerability that fails to correctly invalidate previously used tokens during password reset operations. An attacker in possession of an old token could exploit this flaw, gaining unauthorized access even after the password has been reset. This vulnerability poses a significant risk to the security of user accounts, as it undermines the trust placed in the password reset process. It is essential to upgrade to version 1.1.1 or later to address this issue and enhance user account security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Thorium 1.0.0 < 1.1.1
Thorium 1.1.1
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
