
CVE-2025-10908 Due to a lack of user account state validation during authentication, locked user accounts can be successfully authenticated using Magic Link or Pass Key methods. Thi… https://www.cve.org/CVERecord?id=CVE-2025-10908
Post summary
The post announces CVE‑2025‑10908, detailing an authentication bypass that lets locked accounts be accessed via Magic Link or Pass Key, with no PoC, exploit, or mitigation information provided.

