Intel

AIKIDO-2026-320748

cesargb/laravel-magiclink is vulnerable to Improper Restriction of Excessive Authentication Attempts

Improper Restriction of Excessive Authentication AttemptsGHSA-xc4p-3vgh-p5pf Published Yesterday

74

High Risk

This Affects:

PHPcesargb/laravel-magiclink
2.14.0 - 2.28.0
Fixed in 2.28.1
Are you affected? Scan for Free

TL;DR

The access code challenge for a protected magic link checks a submitted code with Hash::check() and has no attempt counter, lockout, or delay, and the route level rate limit is off by default and keyed by IP rather than by link. Anyone holding a valid access code protected magic link URL can submit unlimited guesses against that link from any IP until the code is found. A correct guess against a link protected with LoginAction gives full authentication as the victim. The fix throttles wrong guesses per magic link and returns a 429 response with a Retry-After header after repeated failures within a configurable window.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you protect a magic link with an access code.

Background info

cesargb/laravel-magiclink is vulnerable to Improper Restriction of Excessive Authentication Attempts in versions 2.14.0 - 2.28.0.

How to fix this

Upgrade the cesargb/laravel-magiclink library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform