Executive brief
AshAuthentication is a library used by Elixir web applications to handle user authentication via OAuth2 providers. A session validation bug allows attackers who intercept an OAuth2 state parameter to bypass authentication controls and force a victim to log into an attacker-controlled account, leading to account takeover.
Technical details
The vulnerability is an insufficient session expiration issue in AshAuthentication.Strategy.OAuth2.Plug.callback/2. The module fails to clear the OAuth2 state value (stored in session_params) when authentication fails, completes, or is cancelled—only clearing it on successful login. Due to incorrect control flow in an Elixir with/else chain, the session entry persists until the next request phase or natural session expiry. An attacker obtaining a victim's OAuth2 state value can replay the OAuth2 callback to authenticate that victim into an attacker-controlled account. The vulnerability affects ash_authentication versions 0.6.0 through 4.15.0 (exclusive) and 5.0.0-rc.0 through 5.0.0-rc.14 (exclusive); patches are available in 4.15.0 and 5.0.0-rc.14 or later.
Affected products
- team-alembic AshAuthentication 0.6.0 to 4.14.x; 5.0.0-rc.0 to 5.0.0-rc.13
Timeline
- 2026-09-17: disclosed