Executive brief
AshAuthentication is an authentication framework used in web applications. A reflected cross-site scripting (XSS) vulnerability in its confirmation and sign-in form pages allows an attacker to inject malicious JavaScript that executes in a user's browser when they follow a crafted link. This could lead to theft of authentication cookies, session hijacking, or credential capture if a victim clicks a malicious confirmation or sign-in link that appears legitimate.
Technical details
The vulnerability is a reflected XSS in the confirm and magic_link form pages of AshAuthentication. The root cause is that request parameters (the confirm parameter in confirmation_form.html.eex and the magic link token parameter in sign_in_form.html.eex) are interpolated directly into hidden input value attributes using unescaped EEx templates (<%= %>) without HTML entity encoding. The accept handlers in both Confirmation.Plug and MagicLink.Plug do not validate or sanitize the parameter values before rendering, and the magic link handler does not verify token signatures at this stage. The attack vector is a crafted GET request; an unauthenticated attacker can terminate the attribute with a quote and inject a <script> element or other markup, which executes in the victim's browser in the application origin's context. The injected script gains access to cookies, session tokens, and same-origin data. Patches are available in versions 4.14.2 and 5.0.0-rc.13 or later.
Affected products
- team-alembic AshAuthentication 4.8.0 to 4.14.1, 5.0.0-rc.0 to 5.0.0-rc.12
Timeline
- 2026-08-25: disclosed