Package
authentik-2026.5
Component
@goauthentik/api
Latest update
5.3
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
The flagged component is the package's locally generated TypeScript API client, whose package.json carries the placeholder version 0.0.0 rather than a release version, causing the scanner to match it against the advisory's vulnerable range (< 2023.5.6). The client is generated from the authentik 2026.5.3 sources, which include the upstream fix for CVE-2023-39522 (username enumeration via the recovery flow, corrected upstream in 2023.5.6 and 2023.6.2), so the vulnerable code version is not present in the package.
Status