Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-54r8-f2jx-5qj6

Опубликовано: 15 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.1
CVSS3: 7.4

Описание

BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows unauthenticated attackers to sign in as arbitrary users by authenticating through a different social provider sharing the same driver_id namespace. Attackers can authenticate at one enabled social provider using a user ID that matches an account linked to a different social provider, bypassing credential verification entirely because the SocialAuthService::handleLoginCallback query ignores the driver column when retrieving linked account records.

BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows unauthenticated attackers to sign in as arbitrary users by authenticating through a different social provider sharing the same driver_id namespace. Attackers can authenticate at one enabled social provider using a user ID that matches an account linked to a different social provider, bypassing credential verification entirely because the SocialAuthService::handleLoginCallback query ignores the driver column when retrieving linked account records.

EPSS

Процентиль: 21%
0.00288
Низкий

9.1 Critical

CVSS4

7.4 High

CVSS3

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 7.4
nvd
8 дней назад

BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows unauthenticated attackers to sign in as arbitrary users by authenticating through a different social provider sharing the same driver_id namespace. Attackers can authenticate at one enabled social provider using a user ID that matches an account linked to a different social provider, bypassing credential verification entirely because the SocialAuthService::handleLoginCallback query ignores the driver column when retrieving linked account records.

EPSS

Процентиль: 21%
0.00288
Низкий

9.1 Critical

CVSS4

7.4 High

CVSS3

Дефекты

CWE-290