GHSA-r3j6-gpjw-qfjr: Medium severity composer/filament/filament vulnerability

Published Sep 1, 2026
·
Updated

A flaw in the handling of one-time codes for app-based multi-factor authentication allows a previously issued code to be used after a newer code has already been accepted. This issue does not affect email-based MFA. Submitting the exact same code twice was already prevented, but any other code within the accepted time window was not.

If an attacker gains access to both the user's password and a single one-time code, that code stays usable for the remainder of its time window, which is around four minutes on the default settings, including after the legitimate user has already logged in with a newer code.

Affected Software

2 affected componentsFixes available
composer/filament/filament>=5.0.0<5.7.6
5.7.6
composer/filament/filament>=4.0.0<4.12.6
4.12.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade composer/filament/filament to a version that resolves this vulnerability.

    Fixed in 5.7.6
  2. Upgrade

    Upgrade composer/filament/filament to a version that resolves this vulnerability.

    Fixed in 4.12.6

Event History

Sep 1, 2026
Advisory Published
via GitHub·09:29 PM
Data Sourced
via GitHub·09:29 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Who is exposed to this issue?

Users authenticated with app-based multi-factor authentication are affected. Email-based MFA is not affected.

2

What does an attacker need to exploit it?

An attacker needs both the user's password and a one-time code issued within the currently accepted time window. A code other than one already submitted can remain usable after the legitimate user logs in with a newer code.

3

Are default settings affected, and how long can a captured code remain usable?

Yes. Under the default settings, the accepted time window is around four minutes, during which a previously issued app-based MFA code may remain usable.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203