{"id":"GHSA-jhmr-57cj-q6g9","aliases":["GO-2025-3873"],"url":"https://o3.security/vulnerability/GHSA-jhmr-57cj-q6g9","summary":"Komari vulnerable to 2FA Authentication Bypass","details":"### Summary\n\nLogic error in 2FA verification condition allows bypass of two-factor authentication\n\n### Details\n\nhttps://github.com/komari-monitor/komari/blob/bd5a6934e1b79a12cf1e6a9bba5372d0e04f3abc/api/login.go#L55\n\nThere is no way for `Verify2Fa` to return an error **AND** true as `ok` at the same time, any codes are considered as valid.\n\n### PoC\n\nUse any 6 digits as 2FA code\n\n### Impact\n\nBypass 2FA Authentication","published":"2025-08-12T00:13:36Z","modified":"2025-08-18T13:57:31.011223Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/komari-monitor/komari","fixedVersion":"0.0.0-20250809064056-cc3d54bff4c6"}],"fix":{"url":"https://github.com/komari-monitor/komari/commit/cc3d54bff4c6495beaa1c7483379cd04542c557f","label":"komari-monitor/komari@cc3d54b"},"references":[{"type":"WEB","url":"https://github.com/komari-monitor/komari/security/advisories/GHSA-jhmr-57cj-q6g9"},{"type":"WEB","url":"https://github.com/komari-monitor/komari/commit/cc3d54bff4c6495beaa1c7483379cd04542c557f"},{"type":"PACKAGE","url":"https://github.com/komari-monitor/komari"},{"type":"WEB","url":"https://github.com/komari-monitor/komari/blob/bd5a6934e1b79a12cf1e6a9bba5372d0e04f3abc/api/login.go#L55"},{"type":"WEB","url":"https://github.com/komari-monitor/komari/releases/tag/1.0.4-fix1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-08-18T13:57:31.011223Z"}}