Impact
The vulnerability in team‑alembic’s AshAuthentication allows an attacker to sign in as an unrelated user by linking a verified OAuth2 identity to that user’s account. The code matches an existing account using credentials other than the email field, and then blindly trusts the provider’s verified flag without comparing the provider email to the stored account email. As a result, an attacker can attach their own OAuth2 account to any existing account and receive a valid session, effectively hijacking that account. The flaw also rewrites the matched account’s email address to the attacker’s, compromising future account recovery and security controls.
Affected Systems
Team‑alembic’s AshAuthentication components are affected in version ranges 4.14.0 to before 4.15.0 and 5.0.0‑rc.10 to before 5.0.0‑rc.14. All installations of AshAuthentication matching those ranges should be treated as vulnerable.
Risk and Exploitability
The CVSS score of 9.1 categorizes the flaw as critical, indicating significant impact and difficulty of exploitation. EPSS information is not available, but the flaw is listed as not included in the CISA KEV catalog. Attackers need only a valid OAuth2 provider account with a verified email; the flaw does not require any special privileges or local access. The attack can be performed remotely via the normal OAuth2 sign‑in or registration path, making it easily exploitable by a wide range of adversaries.
OpenCVE Enrichment