<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Token Leakage (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/token-leak.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/token-leak-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Token Leakage (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:53 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-30845 – Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 throug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30845</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30845</guid>
    <pubDate>Fri, 06 Mar 2026 20:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30845</strong></p>
  <p>Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the board composite publication in Wekan publishes all integration data for a board without any field filtering, exposing sensitive fields including webhook URLs and authentication tokens to any subscriber. Since board publications are accessible to all board members regardless of their role (including read-on…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30845">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48635 – In multiple functions of TaskFragmentOrganizerController.java, there is a possib...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48635</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48635</guid>
    <pubDate>Mon, 02 Mar 2026 19:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48635</strong></p>
  <p>In multiple functions of TaskFragmentOrganizerController.java, there is a possible activity token leak due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48635">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-5386 – In lunary-ai/lunary version 1.2.2, an account hijacking vulnerability exists due...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5386</guid>
    <pubDate>Mon, 02 Feb 2026 11:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-5386</strong></p>
  <p>In lunary-ai/lunary version 1.2.2, an account hijacking vulnerability exists due to a password reset token leak. A user with a 'viewer' role can exploit this vulnerability to hijack another user's account by obtaining the password reset token. The vulnerability is triggered when the 'viewer' role user sends a specific request to the server, which responds with a password reset token in the 'recov…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-66035 – Angular is a development platform for building mobile and desktop web applicatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66035</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66035</guid>
    <pubDate>Wed, 26 Nov 2025 23:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-66035</strong></p>
  <p>Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site Request Forgery (XSRF) to…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-201</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66035">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-23067 – ToolJet versions v0.5.0 to v1.2.2 are vulnerable to token leakage via Referer he...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23067</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23067</guid>
    <pubDate>Wed, 18 May 2022 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-23067</strong></p>
  <p>ToolJet versions v0.5.0 to v1.2.2 are vulnerable to token leakage via Referer header that leads to account takeover . If the user opens the invite link/signup link and then clicks on any external links within the page, it leaks the password set token/signup token in the referer header. Using these tokens the attacker can access the user’s account.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23067">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-23064 – In Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23064</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23064</guid>
    <pubDate>Mon, 02 May 2022 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-23064</strong></p>
  <p>In Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injection. By sending a specially crafted host header in the reset password request, it is possible to send password reset links to users which once clicked lead to an attacker controlled server and thus leading to password reset token leak. This leads to account take over.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23064">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-25602 – Nonce token leak vulnerability leading to arbitrary file upload, theme deletion,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-25602</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-25602</guid>
    <pubDate>Fri, 18 Mar 2022 18:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-25602</strong></p>
  <p>Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings change discovered in Responsive Menu WordPress plugin (versions <= 4.1.7).</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-25602">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-4008 – API Connect V2018.1 through 2018.4.1.1 is impacted by access token leak. Authori...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-4008</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-4008</guid>
    <pubDate>Thu, 07 Feb 2019 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-4008</strong></p>
  <p>API Connect V2018.1 through 2018.4.1.1 is impacted by access token leak. Authorization tokens in some URLs can result in the tokens being written to log files. IBM X-Force ID: 155626.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-4008">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
