GHSA-c785-w9vv-8rm9HighCVSS 8.1

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass...

Published
September 8, 2026
Last Modified
September 8, 2026

🔗 CVE IDs covered (1)

📋 Description

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability where sqlDAL caches empty result sets that writeSql never invalidates. Attackers with a valid password can bypass email two-factor authentication on new devices because the confirmation code hash fails to generate from the stale cached empty result.

🔗 References (4)