HIGH
CVE-2026-71206
CVSS
8.3
Description
Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and returns the embedded claims.Account object unmodified, never re-fetching the account from the database. No session store or token-revocation mechanism exists in the codebase.
Weakness (CWE)
CWE-613
EPSS Score
0.28%
Probability of exploitation in next 30 days
20.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.