← CVEs and Advisories
blueprintue/blueprintue-self-hosted-edition · Severity High (CVSS 7.4) · Discovered by Pavan Nallamothu
Password-reset tokens never expired, so a leaked or intercepted reset link stayed usable indefinitely.
Password-reset tokens have no expiry window.
cve.org record · GitHub Security Advisory GHSA-qr65-6vp8-whjf