CVE-2025-66803 describes a race condition in the Hotwired Turbo framework (versions prior to 8.0.x) that allows session cookies to be reapplied after a logout, effectively preventing successful logout operations. This vulnerability, rated Medium severity (CVSS 4.8), can be triggered by remote attackers through selective network delays or by physically proximate attackers. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion, indicating awareness and potential future interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.0.21CPE matchmatch criteria | cpe:2.3:a:hotwired:turbo:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.