Fix for access control flaw in /auth/passkeys API: enforce userId/passkey validation and WebAuthn credential verification
Security Advisory
Critical
open-reception
Affected:
- open-reception/appointment-booking-software (prior to commit 9304088)
Fixed in:
- commit 9304088
Referenced CVEs:
CVE-2026-54460 · 9.8
文章内图片已隐藏以节省流量 · Upgrade to Pro to view images & offline archive
This content was auto-fetched from github.com, cleaned by our LLM pipeline, and translated to English. View original.