PT-2026-93764 · Npm · @Fastify/Auth
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
@fastify/auth versions 5.0.0 through 5.1.0
Description
This plugin composes multiple authentication and authorization strategies into a single route guard. An issue exists when strategies are composed using the
relation "or" option combined with the run "all" option, and one entry is a nested array acting as an AND group. In this scenario, the group is evaluated in an order-dependent manner where an earlier failing check is silently dropped, and the final result depends solely on the last check. This can lead to an authorization bypass where a request is authorized if it satisfies only the last member of an AND group. A similar order-dependent bypass occurs when the top-level relation is "and" and a nested group uses "or".Recommendations
Update to version 5.1.1 or later.
Omit the
run "all" option where it is not required.
Order each AND group so its stricter check is evaluated last.
Replace nested AND groups with an explicit top-level "and" composition.Exploit
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
@Fastify/Auth