VYPR
Critical severity9.3OSV Advisory· Published Feb 11, 2025· Updated Apr 15, 2026

CVE-2025-24973

CVE-2025-24973

Description

Concorde, formerly know as Nexkey, is a fork of the federated microblogging platform Misskey. Prior to version 12.25Q1.1, due to an improper implementation of the logout process, authentication credentials remain in cookies even after a user has explicitly logged out, which may allow an attacker to steal authentication tokens. This could have devastating consequences if a user with admin privileges is (or was) using a shared device. Users who have logged in on a shared device should go to Settings > Security and regenerate their login tokens. Version 12.25Q1.1 fixes the issue. As a workaround, clear cookies and site data in the browser after logging out.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Nexryai/ConcordeOSV2 versions
    12.119.2-fix.1, 12.119.2-fix.2, 12.119.2-fix.3, …+ 1 more
    • (no CPE)range: 12.119.2-fix.1, 12.119.2-fix.2, 12.119.2-fix.3, …
    • (no CPE)range: <12.25Q1.1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.