CVE-2026-82761 | team-alembic ash_authentication up to 4.14.x/5.0.0-rc.13 Magic Link Jwt.verify toctou

SecurityVulns

A vulnerability classified as critical was found in team-alembic ash_authentication up to 4.14.x/5.0.0-rc.13. This affects the function Jwt.verify of the component Magic Link. The manipulation results in time-of-check time-of-use.

This vulnerability is reported as CVE-2026-82761. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is advised.VulDB Recent EntriesRead More