AgenticJobs Bug Let Anyone Hijack Accounts via Magic Link Rendered in Browser
A security flaw in the AgenticJobs job board platform allowed any visitor to obtain a valid magic-link sign-in for any email address they typed, without owning that address. The bug stemmed from an SMTP configuration field that was declared in code but never backed by an actual mail-sending library, meaning the app always fell through to a dev-only fallback that rendered the login link directly in the browser. Because the magic-link endpoint also auto-created accounts, an attacker could silently take over or create any account with no prior access required. The issue was discovered accidentally when a Resend API call rejected a test address, prompting a closer audit of the authentication flow. Version 0.3.0 patches the flaw by wiring up real email delivery via Resend, ensuring credentials never appear in a browser response under any circumstances.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in