An authentication bypass vulnerability has been found in Repox, which allows a remote user to send a specially crafted POST request, due to the lack of any authentication method, resulting in the alteration or creation of users.
"https://github.com/pypa/advisory-database/blob/main/vulns/repox/PYSEC-2023-293.yaml"