CVE-CVE-2026-71206
Severity
HIGH
CVSS Score
8.3
Description
Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and returns the embedded claims.Account object unmodified, never re-fetching the account from the database. No session store or token-revocation mechanism exists in the codebase....
PoCs for CVE-CVE-2026-71206
CVE-2026-71206-PoC
General
0
Nel-droid
2026-08-16