---
id: CVE-2025-55796
title: >-
  The openml/openml.org web application version v2.0.20241110 uses predictable
  MD5-based tokens for critical user workflows such as signup confirmation,
  password resets, email confirmation resends, and email change confirmation
summary: >-
  The openml/openml.org web application version v2.0.20241110 uses predictable
  MD5-based tokens for critical user workflows such as signup confirmation,
  password resets, email confirmation resends, and email change confirmation.
  These toke…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
vendor: openml
product: openml_frontend
affected:
  - openml_frontend < 2.0.20251111
patched:
  - openml_frontend 2.0.20251111
published: '2025-11-18'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T14:41:38.623'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-55796'
references:
  - url: 'https://github.com/openml'
    label: cve@mitre.org
  - url: 'https://github.com/openml/openml.org'
    label: cve@mitre.org
  - url: >-
      https://github.com/openml/openml.org/security/advisories/GHSA-xfjh-gf9p-8qr6
    label: cve@mitre.org
tags:
  - nvd
epss: 0.00591
epssPercentile: 0.4616
ingestedAt: '2026-09-29T16:39:33.222Z'
---

## Overview

The openml/openml.org web application version v2.0.20241110 uses predictable MD5-based tokens for critical user workflows such as signup confirmation, password resets, email confirmation resends, and email change confirmation. These tokens are generated by hashing the current timestamp formatted as "%d %H:%M:%S" without incorporating any user-specific data or cryptographic randomness. This predictability allows remote attackers to brute-force valid tokens within a small time window, enabling unauthorized account confirmation, password resets, and email change approvals, potentially leading to account takeover.

## Affected

- `openml_frontend < 2.0.20251111`

## Remediation

Upgrade past the affected range:

- `openml_frontend 2.0.20251111`
