CVE-2025-66803
Race condition in the turbo-frame element handler in Hotwired Turbo before 8.0.x causes logout operations to fail when delayed frame responses reapply session cookies after logout.
Does this matter?
Lower severity and a low EPSS score (0.26%). Track it; it rarely justifies an emergency change on its own.
Description
Race condition in the turbo-frame element handler in Hotwired Turbo before 8.0.x causes logout operations to fail when delayed frame responses reapply session cookies after logout. This can be exploited by remote attackers via selective network delays (e.g. delaying requests based on sequence or timing) or by physically proximate attackers when the race condition occurs naturally on shared computers.
- CVSS 3.1
- 4.8 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 0.26% probability · 17th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-362
- Affected
- hotwired/turbo
- Source
- cve@mitre.org
References
- https://github.com/hotwired/turbo/pull/1399Exploit, Issue Tracking, Patch
- https://github.com/hotwired/turbo/security/advisories/GHSA-qppm-g56g-fpvpVendor Advisory
- https://turbo.hotwired.dev/handbook/framesProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.