The #22 bump patched @auth/core to 0.41.3 but trivy also flags the
next-auth package directly (CVE-2026-73420 CRITICAL + CVE-2026-73421,
existence-based auth bypass on configuration errors), both fixed in
5.0.0-beta.32. Tests 80/80 at 100% coverage; typecheck, lint, build
clean.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>