CVE-2026-78154 | the-momentum open-wearables up to 0.6.2 Public Invitation-Code Redemption Endpoint user_invitation_code.py redeem_invitation_code missing authentication
It seems this issue is a false-positive. Please confirm the sources provided and consider disregarding this entry. The endpoint is public on purpose and the invitation code is the credential. This is the standalone SDK onboarding path for mobile apps that have no backend of their own: a developer generates a code via the authenticated dashboard endpoint, the user types it into the app, and it's redeemed for SDK-scoped tokens.