PT-2026-94293 · Hexpm · Ashauthentication

·

CVE-2026-81637

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

2.3

Low

VectorAV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ash authentication versions 0.6.0 through 4.14.9 ash authentication versions 5.0.0-rc.0 through 5.0.0-rc.13
Description Insufficient session expiration allows an attacker who obtains a victim's OAuth2 state value to replay the callback and sign that victim into an attacker-controlled account. The function AshAuthentication.Strategy.OAuth2.Plug.callback/2 fails to clear stored session params during failure paths, such as when the provider returns an access denied error, an invalid code, or a token-exchange error. Because the else block in the Elixir with chain reaches store authentication result/2 while holding the original connection, the session entry is not removed. Consequently, the value intended to protect against Cross-Site Request Forgery (CSRF) is only consumed upon successful authentication and persists after cancelled or failed attempts.
Recommendations Update ash authentication to version 4.15.0 or later. Update ash authentication to version 5.0.0-rc.14 or later.

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81637
GHSA-3VCJ-GXX8-3P44

Affected Products

Ashauthentication