{"id":"GHSA-jhmr-57cj-q6g9","summary":"Komari vulnerable to 2FA Authentication Bypass","details":"### Summary\n\nLogic error in 2FA verification condition allows bypass of two-factor authentication\n\n### Details\n\nhttps://github.com/komari-monitor/komari/blob/bd5a6934e1b79a12cf1e6a9bba5372d0e04f3abc/api/login.go#L55\n\nThere is no way for `Verify2Fa` to return an error **AND** true as `ok` at the same time, any codes are considered as valid.\n\n### PoC\n\nUse any 6 digits as 2FA code\n\n### Impact\n\nBypass 2FA Authentication","aliases":["GO-2025-3873"],"modified":"2025-08-18T13:57:31.011223Z","published":"2025-08-12T00:13:36Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-287"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2025-08-12T00:13:36Z"},"references":[{"type":"WEB","url":"https://github.com/komari-monitor/komari/security/advisories/GHSA-jhmr-57cj-q6g9"},{"type":"WEB","url":"https://github.com/komari-monitor/komari/commit/cc3d54bff4c6495beaa1c7483379cd04542c557f"},{"type":"PACKAGE","url":"https://github.com/komari-monitor/komari"},{"type":"WEB","url":"https://github.com/komari-monitor/komari/blob/bd5a6934e1b79a12cf1e6a9bba5372d0e04f3abc/api/login.go#L55"},{"type":"WEB","url":"https://github.com/komari-monitor/komari/releases/tag/1.0.4-fix1"}],"affected":[{"package":{"name":"github.com/komari-monitor/komari","ecosystem":"Go","purl":"pkg:golang/github.com/komari-monitor/komari"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.0-20250809064056-cc3d54bff4c6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-jhmr-57cj-q6g9/GHSA-jhmr-57cj-q6g9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}