Impact
A flaw in Vendure’s external authentication service allows an attacker to bind an external login to an existing user account without verifying the email address. By supplying a victim’s email address through a custom authentication strategy that does not enforce provider‑verified ownership, the attacker’s external identity becomes linked to the victim’s account. The attacker can then view orders, addresses, and personal information, and may place orders or make account changes as the victim.
Affected Systems
VendureHQ’s Vendure headless commerce platform, all versions published before 3.7.0. Systems using the external authentication service with custom strategies that accept unverified emails are affected. Native‑only email/password deployments and strategies that enforce provider‑verified email are not impacted. New‑account creation for unused emails remains permitted.
Risk and Exploitability
The CVSS score of 9.1 indicates a high‑severity vulnerability. The EPSS score is not available, so the current exploitation likelihood is unclear; the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an external authentication provider that forwards an unverified email address. An attacker exploiting this flaw can bind their external identity to a victim’s account without any additional information, thereby achieving unauthorized access and potential financial fraud.
OpenCVE Enrichment
Github GHSA