QueryWeaver Authentication Bypass Vulnerability Allowing Session Token Issuance for Existing Accounts

Vulnerability

An authentication bypass vulnerability has been identified in QueryWeaver versions through 0.2.0. This vulnerability allows unauthenticated attackers to obtain valid session tokens for existing accounts by sending a signup request with a known victim email address. The issue arises because the signup route creates and links a new token to the corresponding identity before verifying if the email is associated with an existing account. As a result, the server inadvertently returns a valid authenticated session token for the victim's identity, without requiring any prior credentials or user interaction.

Impact

Exploitation of this vulnerability allows for unauthorized access to user accounts by issuing valid session tokens for existing users.

Reproduction

To reproduce this vulnerability, send a signup request to the QueryWeaver application with an email address that belongs to an existing account. The server will respond with a valid session token for that account, bypassing authentication requirements.

Remediation

Users are advised to update QueryWeaver to version 0.3.1 or later, where this vulnerability has been fixed.

Added: Jul 18, 2026, 11:24 PM
Updated: Jul 18, 2026, 11:24 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
8.0
remediation
0.0
relevance
9.6
threat
4.8
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.