THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-wg23-69c2-gjc8 (critical) — Craft CMS: Passkey login accepts replayed WebAuthn assertions

[GHSA] GHSA-wg23-69c2-gjc8 (critical) — Craft CMS: Passkey login accepts replayed WebAuthn assertions

medgithub_advisoriesPublished 2026-08-07

GHSA-wg23-69c2-gjc8 Severity: critical CVE: None

Craft CMS: Passkey login accepts replayed WebAuthn assertions

Craft CMS passkey login accepts WebAuthn requestOptions from the unauthenticated login request body and does not persist the updated credential counter returned by the WebAuthn assertion validator. A captured passkey login request body can therefore be replayed because the old challenge

Original source: https://github.com/advisories/GHSA-wg23-69c2-gjc8