Skip to content

ZITADEL has 1-Click Account Takeover via XSS in /saml-post Endpoint

Critical severity GitHub Reviewed Published Mar 4, 2026 in zitadel/zitadel • Updated Mar 9, 2026

No closed alerts for this advisory

Give feedback on Dependabot alerts