Intel

AIKIDO-2026-10200

robyn is vulnerable to Authentication Bypass

Authentication Bypass Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Feb 21, 2026

90

Critical Risk

This Affects:

PYTHONrobyn
0.0.1 - 0.76.0
Fixed in 0.77.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to an authentication bypass due to improper validation of request headers. The framework incorrectly trusts certain header values when determining the authenticated user, allowing an attacker to craft requests that bypass authentication checks and gain unauthorized access to protected resources.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

robyn is vulnerable to Authentication Bypass in versions 0.0.1 - 0.76.0.

How to fix this

Upgrade the robyn library to the patch version.