Summary

Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled

Advisory details

A flaw in the challenge handling for app-based multi-factor authentication allows the second factor to be bypassed. This issue does not affect email-based MFA. It also only applies when recovery codes are enabled.

References