Auth.js Vulnerability: Homoglyph @ Bypass in Email Normalizer
A critical vulnerability in Auth.js allows an attacker to bypass email validation, potentially leading to account takeover. The flaw affects versions of `next-auth` and `@auth/core` when using the email/magic-link sign-in flow with the default identifier normalizer. Immediate action is required to prevent exploitation.