[GHSA-fg6f-75jq-6523] Authlib has 1-click Account Takeover vulnerability#7260
[GHSA-fg6f-75jq-6523] Authlib has 1-click Account Takeover vulnerability#7260levpachmanov wants to merge 2 commits intolevpachmanov/advisory-improvement-7260from
Conversation
|
Hi there @lepture! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository. This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory |
|
Hi @levpachmanov, I'm not sure why the PR didn't merge, but you have a credit on GHSA-fg6f-75jq-6523 and the changes to the VVR have been incorporated into the global advisory and the CVE record for CVE-2025-68158. |
|
@shelbyc - the most important thing is the fact that the data is correct, thank you! |
Updates
Comments
See the discussion in #7191