Skip to content

ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware

High severity GitHub Reviewed Published Mar 18, 2026 in apostrophecms/apostrophe • Updated Mar 18, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts