-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from insecure user lookup logic in account linking. The commit diff shows removal of username-based lookup in AuthenticationService.php. The vulnerable version used 'username' field (controlled via IDP email) alongside OIDC sub for user matching, enabling attackers to hijack accounts by pre-registering with victim's email as username. The CWE-639 (User-Controlled Key) and CWE-288 (Alternate Auth Path) mappings confirm this pattern matches the described attack vector.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| causal/oidc | composer | >= 3.0.0, < 4.0.0 | 4.0.0 |
Ongoing coverage of React2Shell