GHSA-hj78-p4h7-m5fv
MODERATECVE-2025-24856A vulnerability in the account linking logic of the extension allows a pre-hijacking attack leading to Account Takeover. The attack can only be exploited if the following requirements are met:
- Affected
- >= 3.0.0, < 4.0.0
- Fixed in
- 4.0.0
- Weakness
- CWE-288
- Published
- 2025-01-28
- Source
- github