Intel

AIKIDO-2026-313712

cesargb/laravel-magiclink is vulnerable to Race Condition (TOCTOU)

Race Condition (TOCTOU)GHSA-4426-mcrr-gf94 Published Yesterday

48

Medium Risk

This Affects:

PHPcesargb/laravel-magiclink
2.0.0 - 2.28.0
Fixed in 2.28.1
Are you affected? Scan for Free

TL;DR

A magic link created with a visit limit checks the counter and increments it in two separate steps rather than one atomic update. Concurrent requests against the same link can each pass the limit check before either increment is saved, so the link can be visited more times than the configured limit allows. Applications that leave the visit limit unset are not affected. The fix runs the limit check and increment as one atomic conditional database update.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you set a visit limit on a magic link.

Background info

cesargb/laravel-magiclink is vulnerable to Race Condition (TOCTOU) in versions 2.0.0 - 2.28.0.

How to fix this

Upgrade the cesargb/laravel-magiclink library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform