PT-2026-94298 · Unknown · Ashauthentication
CVSS v4.0
9.1
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
ash authentication versions 3.9.0 through 4.14.9
ash authentication versions 5.0.0-rc.0 through 5.0.0-rc.13
Description
A Time-of-check Time-of-use (TOCTOU) Race Condition occurs when a magic link is configured with
single use token?. This allows an attacker with a leaked magic link to replay a single-use token and authenticate as the target subject. The issue arises because the token validity check is not serialized against its consumption, allowing concurrent redemptions to succeed and yield full user tokens. The sign-in process verifies the JWT using Jwt.verify/4 and revokes it subsequently via AshAuthentication.Strategy.MagicLink.SignInPreparation in a Query.after action callback and AshAuthentication.Strategy.MagicLink.SignInChange in an after transaction hook. Because AshAuthentication.TokenResource.Actions.revoke/3 performs the revocation as an upsert, concurrent duplicate revocations succeed without conflict.Recommendations
Update ash authentication to version 4.15.0 or later.
Update ash authentication to version 5.0.0-rc.14 or later.
Exploit
Fix
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ashauthentication