Product
Sync-in Server v2.3.0 and earlier is vulnerable to a 2FA bypass in the /api/auth/token endpoint, allowing attackers with known credentials to obtain unrestricted JWTs without providing TOTP codes.