{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93340","assignerOrgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","state":"PUBLISHED","assignerShortName":"VulnCheck","dateReserved":"2026-09-17T18:41:40.757Z","datePublished":"2026-09-21T21:21:58.925Z","dateUpdated":"2026-09-21T21:21:58.925Z"},"containers":{"cna":{"providerMetadata":{"orgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","shortName":"VulnCheck","dateUpdated":"2026-09-21T21:21:58.925Z"},"title":"Gladys Assistant < 5.1.0 Password Reset Link Poisoning via forgot_password Endpoint","descriptions":[{"lang":"en","value":"Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password reset tokens for any account by exploiting the client-supplied origin parameter in the forgot_password endpoint without server-side validation. Attackers can send a crafted request specifying an attacker-controlled origin, causing the victim to receive a poisoned reset link that discloses the session token to the attacker, enabling full account takeover including administrator accounts."}],"tags":["x_open-source"],"datePublic":"2026-09-21T00:00:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-640","description":"Weak Password Recovery Mechanism for Forgotten Password","type":"CWE"}]}],"affected":[{"defaultStatus":"unaffected","vendor":"Gladys Assistant","product":"Gladys Assistant","packageURL":"pkg:github/GladysAssistant/Gladys","repo":"https://github.com/GladysAssistant/Gladys","versions":[{"status":"affected","version":"0","versionType":"semver","lessThan":"5.1.0"}]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"ACTIVE","vulnConfidentialityImpact":"HIGH","subConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"HIGH","baseScore":7.4,"vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}},{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","version":"3.1","baseSeverity":"MEDIUM","baseScore":6.8,"vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N"}}],"references":[{"url":"https://gladysassistant.com/blog/gladys-5-1-integration-widgets-and-scenes/","name":"Maintainer Blog","tags":["release-notes"]},{"url":"https://github.com/GladysAssistant/Gladys/releases/tag/v5.1.0","name":"Release Notes","tags":["patch"]},{"url":"https://www.vulncheck.com/advisories/gladys-assistant-password-reset-link-poisoning-via-forgot-password-endpoint","tags":["third-party-advisory"]}],"credits":[{"lang":"en","value":"Pulatjonov Jasurbek","type":"finder"},{"lang":"en","value":"VulnCheck","type":"coordinator"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"vulncheck"}}}}