CVE 7.4 HIGH

Katalyst Koi: Session cookies can be replayed after user logout_CVE-2026-44511

7.4 / 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

Katalyst Koi is a framework for building Rails admin functionality. Prior to 4.20.0 and 5.6.0, admin session cookies were not invalidated when an admin user logged out. An attacker with access to a valid admin session cookie could continue to access admin functionality after logout, until the cookie expired or session secrets were rotated. This vulnerability is fixed in 4.20.0 and 5.6.0.

Basic Information

ID CVE-2026-44511
Source GitHub_M
Published May 14, 2026 at 16:17

Affected Product

Vendor katalyst
Product koi
Version < 4.20.0
Affected Versions katalyst koi < 4.20.0
katalyst koi >= 5.0.0 <= 5.6.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.