GHSA-wg23-69c2-gjc8
CRITICALCraft CMS passkey login accepts WebAuthn requestOptions from the unauthenticated login request body and does not persist the updated credential counter returned by the WebAuthn assertion validator. A captured passkey login request body can therefore be replayed because the old challenge is accepted again, and the stored credential counter remains stale.
- Affected
- >= 5.0.0-RC1, < 5.10.5
- Fixed in
- 5.10.5
- Weakness
- CWE-294
- Published
- 2026-08-07
- Source
- github