VDB
Sign up

EEF-CVE-2026-80218

Sign-in token minted for one resource accepted by another in AshAuthentication

Quick fix

EEF-CVE-2026-80218 — ash_authentication: upgrade to the fixed version with the command below.

mix deps.update ash_authentication

Details

## Summary

Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a sign-in token for one authenticated resource to be signed in as a user of a different resource.

`AshAuthentication.Strategy.Password.SignInWithTokenPreparation.extract_primary_keys_from_subject/2` parses the JWT `sub` claim (for example `user?id=1`) with `URI.parse/1` and keeps only its query string, discarding the path segment that names the subject the token was issued for. Nothing else restores that binding: `AshAuthentication.Jwt.verify/3` checks the signature, `exp`, `nbf`, `jti` and the library-version claims, the purpose check only requires `sign_in`, and the remaining comparison is over primary-key field names, which are identical across resources. The WebAuthn sign-in and remember-me preparations carry copies of the same helper and drop the path in the same way. The magic link sign-in path pins the subject name against the resource and is not affected.

This issue affects ash_authentication: from 3.10.5 before 4.15.0 and from 5.0.0-rc.0 before 5.0.0-rc.14.

Are you affected?

Enter the version of the package you're using.

Affected packages

Hex/ash_authentication
Introduced in: 3.10.5Fixed in: 4.15.0
Fixmix deps.update ash_authentication

References