PT-2026-3642 · Unknown · Hotwired Turbo

Published

2026-01-20

·

Updated

2026-01-21

·

CVE-2025-66803

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Hotwired Turbo versions prior to 8.0.0
Description A race condition exists in the turbo-frame element handler. This issue can cause logout operations to fail when delayed frame responses reapply session cookies after a user has logged out. Attackers can exploit this by introducing selective network delays or by leveraging naturally occurring race conditions on shared computers. This allows remote attackers to restore destroyed session cookies, potentially logging a user back in after they have logged out.
Recommendations Update Hotwired Turbo to version 8.0.0 or later.

Fix

Time Of Check To Time Of Use

Insufficient Session Expiration

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-66803
GHSA-QPPM-G56G-FPVP

Affected Products

Hotwired Turbo