highVulnerability

GHSA-j5rm-v3vh-vx94

### Impact In eduMFA < 2.9.1 userless Passkey/WebAuthn challenges might be replayed and do not expire ### Patches Fixed in eduMFA >= 2.9.1 by adding validity information to the userless challenges. ### Workarounds No known workarounds besides disabling userless login altogether.

Properties

ghsa_id
GHSA-j5rm-v3vh-vx94
severity
high
summary
eduMFA Passkeys: missing expiration flag may allow replay attacks and reuse of old challenges
cve_id
GHSA-j5rm-v3vh-vx94
is_ghsa_only
true
ghsa_published
2026-05-18T15:37:00Z
source_url
https://github.com/advisories/GHSA-j5rm-v3vh-vx94
ghsa_updated
2026-05-18T15:37:01Z

Related Entities (5)

VULNERABLE_TO (1)

[Software]pip/edumfa

AFFECTS (1)

[Software]pip/edumfa

HAS_WEAKNESS (2)

[Weakness]Improper Authentication
[Weakness]Insufficient Session Expiration

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-j5rm-v3vh-vx94 — Ninja Signal Threat Intelligence | Ninja Signal