Vulnerabilities/

Turbo Frame responses can restore stale session cookies

Severity:
Low

Description

A race condition in Turbo Frames allows delayed HTTP responses to restore stale session cookies after session-modifying operations.

Recommendation

Update the @hotwired/turbo package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@hotwired/turbo
Anything's wrong? Let us know Last updated on January 21, 2026