The authentication mechanism is weak enough to be bypassed, guessed, or replayed.
Upgrade, enforce strong authentication (MFA), and invalidate weak sessions.
Use vetted auth with MFA, rate-limit attempts, and never rely on guessable secrets.
Stateward flags Weak Authentication in your own code and dependencies on every pull request.
Scan my repoSources: CISA KEV (public domain), OSV.dev & GitHub Advisory Database (CC-BY-4.0), FIRST EPSS, NVD/CWE (public domain). Served live from the Stateward advisory database.