OpenAEV versions 1.0.0 through 2.0.12 contain a critical account takeover vulnerability in the password reset functionality. The flaw stems from non-expiring password reset tokens that are only 8 digits long, allowing attackers to mass-generate and efficiently brute-force valid tokens to reset any user's password without authentication. Because user email addresses are exposed by design within the platform, even administrator accounts can be compromised with minimal reconnaissance. This vulnerability affects all registered user accounts and enables complete platform compromise through unauthorized access to sensitive simulation data and agent payloads. The vulnerability presents a critical attack surface with a CVSS score of 9.8, requiring no authentication, user interaction, or specialized network access. An unauthenticated remote attacker over the network can execute the attack with low complexity, achieving high impact across confidentiality, integrity, and availability. An automated attack generating 2,000 valid tokens requires approximately 500 seconds to brute-force a password reset token at typical request rates, making this a trivially executable attack that scales reliably across multiple accounts. While not currently listed in the Known Exploited Vulnerabilities catalog, this vulnerability is marked as active on threat tracking lists and has elevated attention from the security community given its severity and ease of exploitation. The EPSS score of 0.0018 indicates this represents a high-risk threat. Organizations running OpenAEV should immediately upgrade to version 2.0.13 to remediate this critical vulnerability, as the attack requires no specialized tools or deep technical knowledge to execute at scale.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.0, < 2.0.13CPE matchmatch criteria | cpe:2.3:a:filigran:openaev:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.