All 5 CVE vulnerabilities found in ash_authentication, with AI-generated Chinese analysis, references, and POCs.
Vendor: team-alembic
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-65633 | Purpose-limited JWT accepted as full bearer authentication in AshAuthentication CWE-287 | 7.6 | High | 2026-08-25 |
| CVE-2026-66882 | Reflected XSS in AshAuthentication confirmation and magic link interaction forms CWE-79 | 2.1 | Low | 2026-08-25 |
| CVE-2026-49757 | OAuth2/OIDC account takeover in AshAuthentication via email-based user matching CWE-290 | - | - | 2026-06-15 |
| CVE-2025-32782 | Ash Authentication email link auto-click account confirmation vulnerability CWE-306 | 5.3 | Medium | 2025-04-15 |
| CVE-2025-25202 | Ash Authentication has flawed token revocation checking logic in actions generated by `mix ash_authentication.install` CWE-269 | 8.2 | - | 2025-02-11 |
All 5 known CVE vulnerabilities affecting ash_authentication with full Chinese analysis, references, and POCs where available.