Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.4

Two-Factor Authentication Bypass in scheb/two-factor-bundle

GHSA-h6mp-mc7g-mg49
Summary

The scheb/two-factor-bundle is vulnerable to a security issue that allows attackers to bypass two-factor authentication. If exploited, this could let attackers access your system without needing a second form of verification. If you're using version 3.7 or earlier, you should update to the latest version as soon as possible.

What to do
  • Update scheb two-factor-bundle to version 3.7.0.
Affected software
Ecosystem VendorProductAffected versions
composer scheb two-factor-bundle >= 3.0.0, < 3.7.0
Fix: upgrade to 3.7.0
Original title
scheb/two-factor-bundle bypass two-factor authentication with unverified JWT trusted device token
Original description
Before version 3.7 the bundle is vulnerable to a [security issue in JWT](https://auth0.com/blog/critical-vulnerabilities-in-json-web-token-libraries/), which can be exploited by an attacker to generate trusted device cookies on their own, effectively by-passing two-factor authentication.
ghsa CVSS3.1 7.4
Vulnerability type
CWE-287 Improper Authentication
Published: 21 May 2024 · Updated: 6 Mar 2026 · First seen: 6 Mar 2026