THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-r3j6-gpjw-qfjr (medium) — Filament: Multi-factor authentication (app) codes can still be used after a newer code has been used

[GHSA] GHSA-r3j6-gpjw-qfjr (medium) — Filament: Multi-factor authentication (app) codes can still be used after a newer code has been used

medgithub_advisoriesPublished 2026-09-01

GHSA-r3j6-gpjw-qfjr Severity: medium CVE: CVE-2026-84306

Filament: Multi-factor authentication (app) codes can still be used after a newer code has been used

A flaw in the handling of one-time codes for app-based multi-factor authentication allows a previously issued code to be used after a newer code has already been accepted. This issue does not affect email-based MFA. Submitting the exact sam

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-r3j6-gpjw-qfjr