CVE-2025-55796 Details
Description
The openml/openml.org web application version v2.0.20241110 uses predictable MD5-based tokens for critical user workflows such as signup confirmation, password resets, email confirmation resends, and email change confirmation. These tokens are generated by hashing the current timestamp formatted as "%d %H:%M:%S" without incorporating any user-specific data or cryptographic randomness. This predictability allows remote attackers to brute-force valid tokens within a small time window, enabling unauthorized account confirmation, password resets, and email change approvals, potentially leading to account takeover.
A vulnerability exists in the OpenML web application version 2.0.20241110, where predictable MD5-based tokens are used for critical user workflows, including signup confirmation, password resets, email confirmation resends, and email change confirmations. These tokens are generated by hashing the current timestamp without incorporating user-specific data or cryptographic randomness, making them predictable. This allows remote attackers to brute-force valid tokens within a short time window, leading to unauthorized account confirmations, password resets, and email change approvals, with the potential for account takeovers.
Users can update to OpenML version 2.0.20251111, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/openml | [email protected] | Product |
| https://github.com/openml/openml.org | [email protected] | Product |
| https://github.com/openml/openml.org/security/advisories/GHSA-xfjh-gf9p-8qr6 | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| openml openml.org | <= 2.0.20241110 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 8, 2026 | Initial Analysis | [email protected] |
| Nov 18, 2025 | CVE Modified | CISA-ADP |
| Nov 18, 2025 | New CVE Received | [email protected] |