SCA: security update for web-auth/webauthn-framework (GHSA-h4fw-6r7f-w494)

high Tenable Self-Hosted Container Security Plugin ID 441493

Description

Webauthn has a User Verification Downgrade via Default-Open ClientOverridePolicy

Solution

Update the web-auth/webauthn-framework library and its related packages to version 5.3.1 or later.

See Also

https://github.com/advisories/GHSA-h4fw-6r7f-w494

Plugin Details

Severity: High

ID: 441493

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 5/8/2026

Updated: 5/8/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/7/2026

Vulnerability Publication Date: 5/7/2026

Reference Information

cwe: CWE-863