Vulnerability DatabaseGHSA-rmmc-8cqj-hfp3

GHSA-rmmc-8cqj-hfp3
JavaScript vulnerability analysis and mitigation

Overview

A high-severity authentication bypass vulnerability was identified in the otpauth npm package (GHSA-rmmc-8cqj-hfp3), affecting versions prior to 3.2.8. The vulnerability was discovered and reviewed on August 31, 2020, published to the GitHub Advisory Database on September 3, 2020, and last updated on January 9, 2023. The issue impacts the authentication mechanism of the otpauth package, which is widely used for implementing One-Time Password (OTP) authentication (GitHub Advisory).

Technical details

The vulnerability stems from a flaw in the totp.validate() function implementation within the otpauth package. The function incorrectly validates single-digit tokens, potentially returning positive values for invalid tokens. This vulnerability is classified under CWE-287 (Improper Authentication) and has been assigned a high severity rating (GitHub Advisory).

Impact

The vulnerability allows potential attackers to bypass OTP authentication mechanisms by submitting single-digit tokens, even when these tokens are invalid. This compromises the security of systems implementing OTP authentication using affected versions of the otpauth package (GitHub Advisory).

Exploitability

The vulnerability can be exploited by submitting single-digit tokens to bypass the OTP authentication mechanism. The simplicity of the exploit method makes this vulnerability particularly concerning for affected systems (GitHub Advisory).

Mitigation and workarounds

Users are strongly advised to upgrade to otpauth version 3.2.8 or later, which contains the fix for this vulnerability. This is the primary and recommended mitigation strategy (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45618CRITICAL10
  • JavaScript logoJavaScript
  • liquidjs
NoYesAug 11, 2026
CVE-2026-48170CRITICAL9.1
  • JavaScript logoJavaScript
  • scim-patch
NoYesAug 07, 2026
CVE-2026-48007HIGH8.6
  • JavaScript logoJavaScript
  • @element-hq/element-call-embedded
NoYesAug 07, 2026
CVE-2026-69207MEDIUM5.3
  • JavaScript logoJavaScript
  • gemini-cli
NoYesAug 07, 2026
CVE-2026-71850MEDIUM4.8
  • JavaScript logoJavaScript
  • langfuse-fips-3
NoYesAug 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management