Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-52xp-w8hr-xv3c

Опубликовано: 01 сент. 2026
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled

A flaw in the challenge handling for app-based multi-factor authentication allows the second factor to be bypassed. This issue does not affect email-based MFA. It also only applies when recovery codes are enabled.

Пакеты

Наименование

filament/filament

composer
Затронутые версииВерсия исправления

>= 4.0.0, < 4.12.0

4.12.0

Наименование

filament/filament

composer
Затронутые версииВерсия исправления

>= 5.0.0, < 5.7.0

5.7.0

EPSS

Процентиль: 44%
0.00551
Низкий

8.1 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 8.1
nvd
около 1 месяца назад

Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to be bypassed when recovery codes are enabled. Email-based multi-factor authentication is not affected. This issue is fixed in versions 4.12.0 and 5.7.0.

EPSS

Процентиль: 44%
0.00551
Низкий

8.1 High

CVSS3

Дефекты

CWE-287