IA Squad
SearchPT

@acastellon/auth

js · @acastellon/authCritical

@acastellon/auth v2.2.0: validateToken() authentication bypass via spoofable headers

In @acastellon/auth v2.2.0, the validateToken() middleware has a service-to-service bypass that can be exploited by an unauthentic

19 Jun 2026 · act now