laravel/fortify is vulnerable to Session Fixation
40
Medium Risk
Affected versions of this package are vulnerable to unauthorized account access due to improper token cleanup after password changes. An attacker could exploit this by reusing an existing password reset link even after the user has changed their password, as the old tokens remain valid, potentially allowing account takeover.
You are affected if you are using a version that falls within the vulnerable range.
laravel/fortify is vulnerable to Session Fixation in versions 1.0.0 - 1.25.4.
Upgrade the laravel/fortify library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant