{"id":"CVE-2026-30224","aliases":["GHSA-gq2m-77hf-vwgh","GO-2026-4623"],"url":"https://o3.security/vulnerability/CVE-2026-30224","summary":"OliveTin: Session Fixation - Logout Fails to Invalidate Server-Side Session","details":"OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, OliveTin does not revoke server-side sessions when a user logs out. Although the browser cookie is cleared, the corresponding session remains valid in server storage until expiry (default ≈ 1 year). An attacker with a previously stolen or captured session cookie can continue authenticating after logout, resulting in a post-logout authentication bypass. This is a session management flaw that violates expected logout semantics. This issue has been patched in version 3000.11.1.","published":"2026-03-06T21:01:37.027Z","modified":"2026-08-07T11:50:51.738394972Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/OliveTin/OliveTin","fixedVersion":"0.0.0-20260304233115-d6a0abc3755d15"}],"fix":{"url":"https://github.com/OliveTin/OliveTin/commit/d6a0abc3755d43107be1939567c52953bcbec3d5","label":"OliveTin/OliveTin@d6a0abc"},"references":[{"type":"WEB","url":"https://github.com/OliveTin/OliveTin/releases/tag/3000.11.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/30xxx/CVE-2026-30224.json"},{"type":"ADVISORY","url":"https://github.com/OliveTin/OliveTin/security/advisories/GHSA-gq2m-77hf-vwgh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-30224"},{"type":"FIX","url":"https://github.com/OliveTin/OliveTin/commit/d6a0abc3755d43107be1939567c52953bcbec3d5"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:50:51.738394972Z"}}