In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover.
https://github.com/muety/wakapi/security/advisories/GHSA-x48w-3rq3-w2pq
https://github.com/muety/wakapi/releases/tag/2.17.6
https://github.com/muety/wakapi/commit/ce91eac2c2d9b29a00873554d2ecef76f10b9087