When using the default implementation of Verify to check a Captcha, verification can be bypassed.
For example, if the first parameter is a non-existent id, the second parameter is an empty string, and the third parameter is true, the function will always consider the Captcha to be correct.
{
"url": "https://pkg.go.dev/vuln/GO-2023-2386",
"review_status": "REVIEWED"
}