A lack of cryptographic signature verification in the...
Critical severity
Unreviewed
Published
Jun 9, 2026
to the GitHub Advisory Database
•
Updated Jun 10, 2026
Description
Published by the National Vulnerability Database
Jun 9, 2026
Published to the GitHub Advisory Database
Jun 9, 2026
Last updated
Jun 10, 2026
A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token.
References