vulns.co
/
GKData.io MCP

Bugsink · 1 min read

Bugsink: time-unit consistency in account-access token expiry

GHSA-4f45-qmjf-82cv describes account-access links whose configured seconds were interpreted as days. The maintainer reports unused email-verification, password-reset and new-user setup tokens surviving their intended lifetime.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

Editorial lesson: represent security durations with explicit units and verify expiration independently of single-use behavior. The maintainer lists versions before 2.5.1 as affected and identifies 2.5.1 as correcting the unit conversion and removing over-age tokens before acceptance.

Before reading

  • Basic server-side identity and authorization concepts

Context and limits

  • Requires possession of an unused token; the advisory says random tokens are not practically guessable. Access remains within the associated account’s permissions, without adding team or project memberships. Successful use deletes the token.
  • The source describes possible unauthorized login after expiry, not a documented production compromise or observed theft. The fix is maintainer-reported; this review did not independently assess deployments or session cleanup.
  • vanschelven published the advisory; no separate reporter is named. The original report date is unknown. Learning prerequisites are editorial.

Sources and provenance

  1. Email verification, password-reset, and new-user setup links remain valid beyond their configured lifetime Bugsink · reviewed 2026-10-03
  2. Bugsink changelog: 2.5.1 Bugsink · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software