Skip to content

[GHSA-g8pg-33v4-9r96] Thelia authentication bypass vulnerability#8012

Open
RainSignal wants to merge 1 commit into
RainSignal/advisory-improvement-8012from
RainSignal-GHSA-g8pg-33v4-9r96
Open

[GHSA-g8pg-33v4-9r96] Thelia authentication bypass vulnerability#8012
RainSignal wants to merge 1 commit into
RainSignal/advisory-improvement-8012from
RainSignal-GHSA-g8pg-33v4-9r96

Conversation

@RainSignal

Copy link
Copy Markdown

Updates

  • Affected products
  • Description

Comments
The advisory states the vulnerability is present from 2.1.0-beta1,
but code review shows this is incorrect. We examined the file
TokenProvider.php across multiple versions and confirmed the
vulnerable unserialize() code exists in all of them:

Since 2.0.0-RC1 is the earliest version we checked and already
contains the vulnerable code, the affected version range should
be updated to >= 2.0.0-RC1. The true introduction point may be
even earlier, but we could not confirm versions prior to 2.0.0-RC1.

Therefore, the affected versions should be changed from
">= 2.1.0-beta1, < 2.1.3" to "< 2.1.3".

Copilot stopped work on behalf of RainSignal due to an error June 11, 2026 15:50
@github-actions github-actions Bot changed the base branch from main to RainSignal/advisory-improvement-8012 June 11, 2026 15:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant