supertokens-node is vulnerable to Use of Single-factor Authentication
10
Low Risk
Affected versions of this package fail to validate the MFA (Multi-Factor Authentication) claim before allowing the removal of a TOTP (Time-Based One-Time Password) device. This vulnerability can allow attackers to bypass multi-factor authentication protections and disable a user's TOTP device without proper verification.
You are affected if you are using a version which is within vulnerability ranges
supertokens-node is vulnerable to Use of Single-factor Authentication in versions 17.0.0 - 17.1.4, 18.0.0 - 18.0.2, 19.0.0 - 19.0.1, 20.0.0 - 20.1.5 and 21.0.0 - 21.0.0.
Upgrade the supertokens-node library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant