Executive brief
AshAuthenticationPhoenix is an authentication library for Elixir/Phoenix web applications. After a user signs in with their password, the application redirects the browser to a special link containing a single-use authentication token in the URL. This token gets recorded in web server logs, proxy logs, browser history, and other places that are typically less secured than session cookies, allowing anyone with access to these logs to impersonate the user.
Technical details
The vulnerability is improper credential handling in HTTP requests (CWE-598). The AshAuthentication.Phoenix.Components.Password.SignInForm component constructs a sign_in_with_token redirect path using a freshly-issued user authentication token as a query parameter, transmitting it via GET request. This causes the sensitive token to appear in the HTTP request line, where it is logged by web servers, reverse proxies, request telemetry systems, and browser history—all of which typically persist longer than a session and have weaker access controls. While the redirect destination is restricted to local paths (preventing open redirect), the live credential remains exposed in logged artifacts. The vulnerability affects ash_authentication_phoenix versions 1.7.0 before 2.17.4 and 3.0.0-rc.0 before 3.0.0-rc.11, as well as ash_authentication versions 3.10.5 before 4.15.0 and 5.0.0-rc.0 before 5.0.0-rc.14. Patches are available in fixed versions.
Affected products
- team-alembic AshAuthenticationPhoenix 1.7.0 before 2.17.4 and 3.0.0-rc.0 before 3.0.0-rc.11
- team-alembic AshAuthentication 3.10.5 before 4.15.0 and 5.0.0-rc.0 before 5.0.0-rc.14
Timeline
- 2026-09-17: disclosed