The CVE Program has published a record for a vulnerability in Pocketbase, a Go package, which could lead to unhandled panic in worker goroutines. The NVD entry is currently unknown. The vulnerability was reported by osv_dev via a source item. There are multiple references to source code changes and discussions related to this issue. Defenders should assess the potential impact and verify exposure of syste [truncated]
PocketBase versions prior to 0.22.42 and 0.37.4 contain an authentication bypass vulnerability in their OAuth2 user linking mechanism. An attacker who knows a victim's email address can pre-create an unverified PocketBase user account by authenticating with one OAuth2 provider (e.g., Provider A). When the legitimate victim later signs up or is invited using a different OAuth2 provider (Provider B), Pocket [truncated]