GHSA-wmm3-h9qj-p5v6

Suggest an improvement
Source
https://github.com/advisories/GHSA-wmm3-h9qj-p5v6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-wmm3-h9qj-p5v6/GHSA-wmm3-h9qj-p5v6.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-wmm3-h9qj-p5v6
Aliases
Published
2026-05-12T22:23:20Z
Modified
2026-06-09T10:45:18Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
SillyTavern: Existing sessions are not invalidated after password change, allowing session reuse and account takeover
Details

Summary

Changing a user’s password does not invalidate existing sessions, allowing an attacker with a stolen cookie to retain access even after the victim resets their password.

Details

SillyTavern relies on cookie-session for authentication, storing all session data (user handle, permissions) in a signed cookie. The endpoints POST /api/users/change-password and POST /api/users/recover-step2 only update the password hash in the database but do not expire current sessions. Because the session is stateless and stored entirely in the client cookie, there is no server-side mechanism to revoke a token once issued.

PoC

1.Log into the same SillyTavern account from two different browsers (e.g., Chrome and Firefox private mode). 2.In Chrome, change the account password under User Settings → Change Password. 3.In Firefox, refresh the page or perform a protected action (e.g., view API keys). 4.Expected: Firefox session should be invalidated and ask for login. 5.Actual: Firefox remains fully authenticated, able to perform all actions as the targeted user.

Impact

An attacker who obtains a valid session cookie (via XSS, MITM, physical access, etc.) can continue using it indefinitely, even after the legitimate user changes their password. This nullifies the most common recovery measure against session theft. The default cookie lifespan is 400 days, giving an attacker a very long exploitation window.

Resolution

A fix was released in the version 1.18.0, invalidating a session cookie on account password change.

Database specific
{
    "cwe_ids":  [
        "CWE-613"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-05-12T22:23:20Z",
    "nvd_published_at":  "2026-05-29T19:16:24Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / sillytavern

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.18.0

Database specific

last_known_affected_version_range
"<= 1.17.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-wmm3-h9qj-p5v6/GHSA-wmm3-h9qj-p5v6.json"