ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware
High severity
GitHub Reviewed
Published
Mar 18, 2026
in
apostrophecms/apostrophe
•
Updated Mar 18, 2026
Give feedback on Dependabot alerts