CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



GHSA-WG23-69C2-GJC8

GHSA-WG23-69C2-GJC8: Passkey Login Replay Vulnerability in Craft CMS

Alon Barad
Alon Barad
Software Engineer

Aug 7, 2026·6 min read·19 visits

Executive Summary (TL;DR)

Craft CMS native Passkey authentication fails to securely validate challenge options and discard/update the signature counter, allowing complete authentication bypass via captured request replay.

GHSA-WG23-69C2-GJC8 is a critical security vulnerability discovered in the native Passkey (WebAuthn) login implementation of Craft CMS. The vulnerability allows an attacker to bypass WebAuthn's core cryptographic challenge-response and signature-counter replay protections. By intercepting a single successful passkey login request body, an attacker can replay the identical request payload to generate additional authenticated active sessions, resulting in complete account takeover.

Vulnerability Overview

Craft CMS versions 5.0.0-RC1 through 5.10.4.1 contain an authentication bypass vulnerability within the native Passkey (WebAuthn) login implementation. This flaw allows an attacker to reuse a captured WebAuthn authentication assertion to establish unauthorized sessions. The vulnerability represents a failure to enforce core WebAuthn security specifications on the server side.

The vulnerable component resides in the core authentication handling logic, specifically within the controller and service classes responsible for validating WebAuthn assertions. Under normal conditions, WebAuthn relies on strict cryptographic challenge-response mechanisms and monotonically increasing counters to prevent replay attacks. These protections ensure that each login assertion is unique and used exactly once.

Due to implementation errors in Craft CMS, both the session challenge validation and the signature counter tracking were rendered ineffective. Consequently, any attacker capable of intercepting a valid passkey authentication request can replay the payload to achieve full account takeover. The flaw requires no special privileges and bypasses standard multi-factor authentication controls.

Root Cause Analysis

The vulnerability is a classic representation of CWE-294 (Authentication Bypass by Capture-replay) and is caused by two distinct software design failures. First, the application's passkey login controller deserialized the cryptographic challenge options directly from the client's unauthenticated HTTP request body. It did not verify them against a server-side session variable.

By trusting the client-supplied requestOptions parameter, the application allowed an attacker to supply a historic challenge value alongside a historic signature. The server validated the signature against the self-supplied challenge within the request, neutralizing the security guarantee of the challenge-response mechanism. This eliminated the temporal uniqueness constraint required by WebAuthn.

Second, the application failed to persist the updated signature counter (signCount) returned by the WebAuthn validation library. While the library successfully verified the assertion and returned an updated credential source object with an incremented counter, the application discarded this returned object. As a result, the database copy of the signature counter remained permanently static, rendering clone detection and replay prevention checks non-functional.

Code Analysis

The execution flow for the vulnerability involves the controller extracting client parameters and passing them directly to the verification service. The diagram below illustrates how the validation checks succeed despite using replayed data.

The vulnerable controller code in src/controllers/UsersController.php extracted the challenge options directly from the POST request body:

// Vulnerable: Reads challenge options from client request
$requestOptions = $this->request->getRequiredBodyParam('requestOptions');

The patch resolves this by reading the challenge parameters directly from the user's secure session and deleting the variable to prevent subsequent reuse:

// Patched: Extracts and removes options from server-side session
$requestOptions = SessionHelper::remove(Craft::$app->getAuth()->passkeyRequestOptionsParam);
if (!$requestOptions) {
    return $this->asFailure(Craft::t('app', 'Passkey authentication failed.'));
}

In src/services/Auth.php, the verification function initially verified the key but failed to capture or persist the updated key source:

// Vulnerable: Output of check() containing updated counter is discarded
$this->webauthnServer()->getAuthenticatorAssertionResponseValidator()->check(
    $publicKeyCredentialSource,
    $authenticatorAssertionResponse,
    $publicKeyCredentialRequestOptions,
    Craft::$app->getRequest()->getHostName(),
    $userEntity->id,
);

The patched service captures the output and caches it in the session temporarily:

// Patched: Captures and caches the updated credential source
$updatedPublicKeyCredentialSource = $this->webauthnServer()->getAuthenticatorAssertionResponseValidator()->check(
    $publicKeyCredentialSource,
    $authenticatorAssertionResponse,
    $publicKeyCredentialRequestOptions,
    Craft::$app->getRequest()->getHostName(),
    $userEntity->id,
);
SessionHelper::set($this->passkeyCredSourceParam, $updatedPublicKeyCredentialSource);

Finally, src/elements/User.php retrieves the updated source from the session and commits the new signature counter to the database:

// Patched: Commits the new counter to the repository
$updatedPublicKeyCredentialSource = Session::remove($authService->passkeyCredSourceParam);
$authService->webauthnServer()->getCredentialRepository()->saveCredentialSource($updatedPublicKeyCredentialSource);

Exploitation Methodology

Exploiting this vulnerability requires the interception of a single valid Passkey authentication payload. An attacker must monitor or retrieve the raw HTTP request body transmitted during a legitimate user's login sequence to /actions/users/login-with-passkey. This can be achieved through network monitoring, server log exposure, or client-side compromise.

Once the payload is captured, the attacker can replay the identical JSON request body to the target application. Because the application uses the request's own client-supplied challenge options, the cryptographic verification succeeds. The server assumes the assertion is fresh because it is matched against the accompanying replayed challenge.

Because the application does not persist the updated signature counter, the server-side validator compares the replayed counter against a static database value. This allows the request to bypass both WebAuthn challenge verification and signature-counter freshness checks. The server then generates a new session cookie for the attacker, resulting in immediate session takeover.

Impact Assessment

The impact of this vulnerability is classified as critical, carrying a CVSS v4 score of 9.1. An attacker who successfully replays a captured assertion gains full access to the target user account, which may include administrative privileges depending on the compromised user's role. This bypasses the multi-factor authentication guarantees typically provided by physical security keys.

This vulnerability undermines the primary security assumption of WebAuthn and Passkeys, which are designed to resist replay and credential-harvesting attacks. If passkey authentication is the primary factor of authentication, the bypass allows direct administrative access to the Craft CMS control panel.

With administrative access, an attacker can modify template files, execute arbitrary code via server configuration parameters, extract database contents, or completely deface the hosted web application. The lack of a corresponding CVE does not minimize the severity of this flaw, as it represents a complete authentication failure within a core identity component.

Remediation and Mitigation

The primary remediation path is upgrading the Craft CMS framework to version 5.10.5 or later. Administrators can perform this update via Composer by running the command composer update craftcms/cms --with-dependencies inside their root project directory.

If an immediate upgrade is not possible, administrators should disable the native Passkey (WebAuthn) login feature within the application's authentication configuration. This restricts users to standard password-based login or alternative multi-factor authentication methods that do not rely on the vulnerable WebAuthn wrapper.

Security teams can detect potential historical exploitation by querying the database table webauthnrecords. A signature counter that remains static across multiple successful login events for a single passkey indicates that the vulnerable code path was executed without updating the state.

Official Patches

Craft CMSOfficial patch fixing Passkey verification and session state usage.

Fix Analysis (1)

Technical Appendix

CVSS Score
9.1/ 10
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Systems

Craft CMS installations utilizing native Passkey (WebAuthn) authentication

Affected Versions Detail

Product
Affected Versions
Fixed Version
craftcms/cms
Craft CMS
>= 5.0.0-RC1, < 5.10.55.10.5
AttributeDetail
CWE IDCWE-294
Attack VectorNetwork (AV:N)
CVSS v4 Score9.1 (Critical)
Exploit StatusPoC / Known Mechanics
ImpactAuthentication Bypass / Account Takeover

MITRE ATT&CK Mapping

T1556Modify Authentication Process
Credential Access
T1212Exploitation for Credential Access
Credential Access
T1563Subvert Active Sessions
Lateral Movement
CWE-294
Authentication Bypass by Capture-replay

The application receives sensitive authentication credentials and accepts them on subsequent requests without sufficient validation of freshness or uniqueness.

Known Exploits & Detection

GitHub Security AdvisoryInformation regarding verification of passkey assertions and signature counter handling.

Vulnerability Timeline

Craft CMS 5.0 is released, introducing native Passkey (WebAuthn) authentication support.
2024-05-01
GHSA-wg23-69c2-gjc8 is published to the GitHub Advisory Database after coordinated disclosure.
2026-08-07
Craft CMS releases version 5.10.5 containing the patch.
2026-08-07

References & Sources

  • [1]GHSA-WG23-69C2-GJC8: Craft CMS Passkey Login Replay Vulnerability
  • [2]Craft CMS Fix Commit
  • [3]Craft CMS Release 5.10.5
  • [4]Craft CMS Repository

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•18 minutes ago•CVE-2026-105749
6.5

CVE-2026-105749: Unbounded Table Attributes in Docling Backends Leads to Resource Exhaustion

An uncontrolled resource consumption vulnerability exists in the Docling document conversion library. Maliciously structured HTML, JATS, ODS, or BoxNote inputs containing table cells with excessively large 'rowspan' or 'colspan' attribute values trigger algorithmic complexity conditions. This allows unauthenticated remote attackers to initiate resource exhaustion states, crashing or hanging the target document processing pipeline while bypassing configured timeouts.

Amit Schendel
Amit Schendel
0 views•6 min read
•about 1 hour ago•CVE-2026-105748
4.3

CVE-2026-105748: Local File Inclusion and Arbitrary File Disclosure in Docling Document Parser

A Local File Inclusion (LFI) and Arbitrary File Disclosure vulnerability exists in Docling and Docling Slim versions >= 2.16.0 up to 2.131.0. When parsing serialized DoclingDocument structures using the JSON input format, the backend fails to restrict image URI schemes, allowing remote attackers to retrieve local files and verify path existence on the host system during embedded document export.

Amit Schendel
Amit Schendel
3 views•5 min read
•about 2 hours ago•CVE-2026-105744
7.5

CVE-2026-105744: Arbitrary File Read and Remote Code Execution in Docling Tectonic Engine

Docling, a tool for parsing and processing diverse document formats, is vulnerable to arbitrary file read, arbitrary file write, and potential remote code execution (RCE) in versions 2.94.0 through 2.131.0. The vulnerability occurs when applications configure Docling to use the Tectonic engine for rendering TikZ diagrams into images. Because the compilation did not restrict hazardous TeX primitives or sandbox the environment, an attacker can supply crafted documents containing malicious TikZ definitions to access or modify local files and execute arbitrary commands under the privileges of the processing application.

Amit Schendel
Amit Schendel
4 views•7 min read
•about 3 hours ago•CVE-2026-105743
4.0

CVE-2026-105743: Server-Side Request Forgery Guard Bypass in Docling Document Conversion Engine

An SSRF guard bypass vulnerability in the Docling document conversion engine allows unauthenticated attackers to bypass internal IP access controls. The vulnerability exists due to a DNS rebinding Time-of-Check Time-of-Use (TOCTOU) condition, URL authority parsing inconsistencies, and unvalidated network requests triggered during headless browser page rendering.

Amit Schendel
Amit Schendel
4 views•6 min read
•about 4 hours ago•CVE-2026-105742
3.7

CVE-2026-105742: Sensitive Custom Header Leakage in Docling Image Resource Loader

A technical analysis of CVE-2026-105742 (GHSA-p3fw-7699-7926), a sensitive information disclosure vulnerability in the Docling document processing library. Vulnerable versions of Docling indiscriminately forward custom HTTP headers, such as authentication tokens, to arbitrary third-party origins and during cross-origin redirects while fetching remote image assets from untrusted HTML and EPUB documents.

Alon Barad
Alon Barad
5 views•6 min read
•about 5 hours ago•CVE-2026-106121
4.9

CVE-2026-106121: Denial of Service via Infinite Loop in RabbitMQ Java Client JSON Parser

CVE-2026-106121 is a Denial of Service (DoS) vulnerability in the RabbitMQ Java Client library (amqp-client) affecting versions prior to 5.37.0. The vulnerability resides in the legacy, custom JSON-RPC parsing class com.rabbitmq.tools.json.JSONReader. When parsing malformed or truncated payloads ending within a quoted string or single-line comment, the parser's scanner enters an infinite loop. This occurs because the loop lacks an exit condition for the end-of-input sentinel character returned by the iterator, leading to either CPU exhaustion or a JVM crash from an OutOfMemoryError.

Amit Schendel
Amit Schendel
7 views•6 min read