• Sources: advisory, release
  • Summary: Craft CMS accepted a WebAuthn assertion that had already been used, so a captured passkey login request body authenticates again. GHSA-wg23-69c2-gjc8 gives the affected range as 5.0.0-RC1 up to but excluding 5.10.5, patched in 5.10.5. GitHub rates it Critical at CVSS 9.1 and no CVE is assigned. The advisory was published in the craftcms/cms repository on 2026-07-25 and entered the GitHub Advisory Database on 2026-08-07.
  • Why it matters: One captured login request creates further authenticated sessions for that account, which removes the one-time challenge guarantee that passkeys are chosen for.

send feedback on this story