PatchSiren

team-alembic CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW team-alembic CVE published 2026-08-25

CVE-2026-66882

The CVE-2026-66882 vulnerability is a reflected cross-site scripting (XSS) vulnerability in the AshAuthentication library. This occurs when a strategy is configured with require_interaction? set to true, allowing an attacker to craft a URL that injects malicious code into the page. The vulnerability affects versions 4.8.0 to 4.14.2 and 5.0.0-rc.0 to 5.0.0-rc.13 of the ash_authentication library. To addres [truncated]

HIGH team-alembic CVE published 2026-08-25

CVE-2026-65633

The CVE-2026-65633 Improper Authentication vulnerability in team-alembic AshAuthentication allows purpose-limited JWTs to be replayed as full bearer API credentials when a resource uses stateless bearer-token verification. This vulnerability affects ash_authentication from 3.10.5 before 4.14.2 and from 5.0.0-rc.0 before 5.0.0-rc.13. The vulnerability can be exploited by an attacker who obtains a not-yet-e [truncated]

CRITICAL team-alembic CVE published 2026-06-15

CVE-2026-49757

CVE-2026-49757 is a critical vulnerability in AshAuthentication, a library used for authentication in Elixir applications. The vulnerability allows an attacker to bypass authentication and take over a local user's account using OAuth2 or OIDC sign-in. This is possible because AshAuthentication's OAuth2 and OIDC strategies match local users by email address instead of the OpenID Connect iss/sub claim combi [truncated]