Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6j36-r6pr-59x4 | Vendure affected by external-authentication account takeover: external login linked to a pre-existing account by email without verification |
Thu, 17 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vendure
Vendure vendure |
|
| Vendors & Products |
Vendure
Vendure vendure |
Thu, 17 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 17 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.createCustomerAndUser in packages/core/src/service/helpers/external-authentication/external-authentication.service.ts selects an existing customer user by emailAddress and attaches a newly presented ExternalAuthenticationMethod without requiring verified to be true. In deployments with a custom external AuthenticationStrategy that forwards an email whose ownership the provider has not verified, an attacker can authenticate with a victim's email and bind the attacker's external identity to the victim's existing account. This can expose orders, addresses, and personal information and permit account changes or orders as the victim. Native-only email and password deployments and external strategies that always require provider-verified email ownership are unaffected, and new-account creation for an unused email remains permitted. This issue is fixed in version 3.7.0. | |
| Title | Vendure: External-authentication account takeover: external login linked to a pre-existing account by email without verification | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-17T15:21:11.192Z
Reserved: 2026-07-16T21:37:45.769Z
Link: CVE-2026-63472
Updated: 2026-09-17T15:21:03.123Z
Status : Deferred
Published: 2026-09-17T15:16:49.743
Modified: 2026-09-17T21:16:02.560
Link: CVE-2026-63472
No data.
OpenCVE Enrichment
Updated: 2026-09-17T20:45:16Z
Github GHSA