Existing sessions stayed valid after a credential change, so a stolen session survived the very password reset meant to revoke it.
Active sessions are not invalidated after a password change or reset.
cve.org record · GitHub Security Advisory GHSA-gqpq-x62g-p4mg