Unauthenticated route is used to invite users

This page is not yet available in Spanish. We are working on its translation.
If you have any questions or feedback about our current translation project, feel free to reach out to us!

Description

An unauthenticated API route is being used to handle user invitations, which may expose your application to potential security risks.

A malicious actor could abuse this endpoint to send unauthorized invitations, potentially leading to account enumeration, spamming, or social engineering attacks.

Remediation

  • Validate that the code isn’t expecting the user to be authenticated to have access to this resource (AuthN). If this API is in fact authenticated, ensure your code is instrumented correctly.