VYPR
Critical severity9.1NVD Advisory· Published Jan 28, 2026· Updated Jun 17, 2026

CVE-2025-69602

CVE-2025-69602

Description

A session fixation vulnerability exists in 66biolinks v62.0.0 by AltumCode, where the application does not regenerate the session identifier after successful authentication. As a result, the same session cookie value is reused for users logging in from the same browser, allowing an attacker who can set or predict a session ID to potentially hijack an authenticated session.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • AltumCode/66biolinksllm-fuzzy3 versions
    =62.0.0+ 2 more
    • (no CPE)range: =62.0.0
    • cpe:2.3:a:altumcode:66biolinks:62.0.0:*:*:*:*:*:*:*
    • (no CPE)

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.