Junglewise Threat Intelligence

spomky-labs/otphp: Mass-assignment in Factory::loadFromProvisioningUri lets a hostile provisioning URI corrupt OTP state or leak an uncaught

Severity: medium · CVSS 4 · Published 2026-06-18

Vendors: Packagist.

Executive brief

spomky-labs/otphp: Mass-assignment in Factory::loadFromProvisioningUri lets a hostile provisioning URI corrupt OTP state or leak an uncaught TypeError

Affected products

  • Packagist spomky-labs/otphp

Related threats