Intel

AIKIDO-2025-10953

spryker/security-gui is vulnerable to Auth Bypass

Auth Bypass Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Dec 15, 2025

60

Medium Risk

This Affects:

PHPspryker/security-gui
1.10.0 - 2.0.2
Fixed in 2.1.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Multi-Factor Authentication Bypass via Improper Code Invalidation due to an adjusted user authentication flow that invalidates active MFA codes before login and verifies login status during validation. This flaw allows an attacker to invalidate a user's MFA codes prematurely, potentially bypassing MFA requirements or causing login failures. An attacker could exploit this by initiating login attempts that trigger MFA invalidation without completing authentication, leading to account lockout or unauthorized access if the system fails to properly validate the user's login state during MFA verification.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

spryker/security-gui is vulnerable to Auth Bypass in versions 1.10.0 - 2.0.2.

How to fix this

Upgrade the spryker/security-gui library to the patch version.