@convex-dev/auth is vulnerable to Improper Restriction of Excessive Authentication Attempts
74
High Risk
Applications built with Convex Auth that use an email or phone one-time-password provider verify sign-ins by checking a short numeric code sent to the user. The verification path does not effectively restrict how many code guesses can be made, so short numeric codes with fewer than eight digits can be guessed through repeated unauthenticated attempts within the code lifetime. A party who guesses a valid code can complete sign-in as the targeted user without any prior access. The fix corrects verification-code handling so a code is validated and consumed correctly, closing the brute-force path.
You are affected if you are using a version that falls within the vulnerable range and your application uses an email or phone one-time-password (OTP) provider with short numeric codes.
@convex-dev/auth is vulnerable to Improper Restriction of Excessive Authentication Attempts in versions 0.0.1 - 0.0.94.
Upgrade the @convex-dev/auth library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant