Authentication can be bypassed or spoofed, letting an attacker act as another user.
Upgrade to the patched release and rotate any exposed credentials/sessions.
Use a vetted auth library, verify every token server-side, and fail closed.
Stateward flags Improper Authentication in your own code and dependencies on every pull request.
Scan my repoSources: CISA KEV (public domain), OSV.dev & GitHub Advisory Database (CC-BY-4.0), FIRST EPSS, NVD/CWE (public domain). Served live from the Stateward advisory database.