@acastellon/auth
js · @acastellon/authCritical
@acastellon/auth v2.2.0: validateToken() authentication bypass via spoofable headers
In @acastellon/auth v2.2.0, the validateToken() middleware has a service-to-service bypass that can be exploited by an unauthentic
19 Jun 2026 · act now