Skip to content

SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking

High severity GitHub Reviewed Published Mar 30, 2026 in scitokens/scitokens

No open alerts for this advisory

Give feedback on Dependabot alerts