How to use this reference
Editorial lesson: represent security durations with explicit units and verify expiration independently of single-use behavior. The maintainer lists versions before 2.5.1 as affected and identifies 2.5.1 as correcting the unit conversion and removing over-age tokens before acceptance.
Before reading
- Basic server-side identity and authorization concepts
Context and limits
- Requires possession of an unused token; the advisory says random tokens are not practically guessable. Access remains within the associated account’s permissions, without adding team or project memberships. Successful use deletes the token.
- The source describes possible unauthorized login after expiry, not a documented production compromise or observed theft. The fix is maintainer-reported; this review did not independently assess deployments or session cleanup.
- vanschelven published the advisory; no separate reporter is named. The original report date is unknown. Learning prerequisites are editorial.
Sources and provenance
- Email verification, password-reset, and new-user setup links remain valid beyond their configured lifetime Bugsink · reviewed 2026-10-03
- Bugsink changelog: 2.5.1 Bugsink · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.