← Reference
Access control

A password reset link can be used to enter someone else's…

Insecure password reset token handling

What this means

The password recovery link is predictable, never expires, or works more than once. Whoever obtains or guesses it can sign in as that user.

Why it matters

Password recovery is a side door to every account. One weak link cancels out strong passwords and two-factor sign-in alike.

How to fix it

  • Make reset links random and long, valid for no more than an hour.
  • Invalidate the link immediately after first use and after any password change.

Prompt for your AI agent

Make password reset links single-use, random and short-lived. After a link is used it must stop working.

Verify the fix: open a used recovery link a second time — expect a refusal

ClassificationCWE-640CWE-522· API2:2023 · A07:2021
Referencescwe.mitre.org
Is your app doing this?
Find out in about a minute — the first scan is free.
Scan your app
A password reset link can be used to enter someone else's…