CISA Thorium does not properly invalidate previously used tokens when resetting passwords. An attacker that possesses a previously used token could still log in after a password reset. Fixed in 1.1.1.
{
"cwe_ids": [
"CWE-613"
],
"cna_assigner": "cisa-cg",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/35xxx/CVE-2025-35433.json"
}