{"id":"GHSA-6j36-r6pr-59x4","summary":"Vendure affected by external-authentication account takeover: external login linked to a pre-existing account by email without verification","details":"# External-authentication account takeover: external login linked to a pre-existing account by email without requiring verification\n\n**Package:** @vendure/core (vendure-ecommerce/vendure, latest master) · \n\n\u003e [!IMPORTANT]\n\u003e This vulnerability **only affects deployments that use external / social authentication**\n(an `AuthenticationStrategy` other than the built-in native email/password strategy) where\nthat strategy can return an email address the external provider has **not verified** the\nuser owns.\n\n**You are affected if all of these are true:**\n- Your store configures one or more external `AuthenticationStrategy` implementations\n  (custom OAuth / social login / SSO), **and**\n- At least one forwards an `emailAddress` to `ExternalAuthenticationService` without\n  guaranteeing the provider verified ownership of it (e.g. it doesn't check the provider's\n  `email_verified` claim, or leaves `verified` unset/false), **and**\n- Customer accounts exist that share an email address with those external identities.\n\n**You are NOT affected if:**\n- You use only the built-in native (email/password) authentication with no external strategies, **or**\n- Every external strategy you use only ever returns provider-verified emails (and sets `verified: true`).\n\n**Remediation:** Upgrade to **3.7.0**. After upgrading, an external login is only linked to a\npre-existing account when the email is verified; a custom `AuthenticationStrategy` must set\n`verified: true` only for emails the provider has actually verified.\n\n## Summary\n`ExternalAuthenticationService.createCustomerAndUser()` links a newly-presented external (OAuth/social) authentication method to a **pre-existing User account selected purely by email-address match**, and it does so **without requiring `config.verified === true`**. If any configured `AuthenticationStrategy` forwards an email that was not proven to belong to the external identity (the classic `email_verified` omission — common with custom OAuth providers, or providers/strategies that don't validate email ownership), an attacker can register at that provider using a victim's email address, authenticate, and have their external identity bound to the victim's existing Vendure account — resulting in account takeover.\n\n## Vulnerable code\n`packages/core/src/service/helpers/external-authentication/external-authentication.service.ts` — `createCustomerAndUser`:\n```ts\nconst existingUser = await this.findExistingCustomerUserByEmailAddress(ctx, config.emailAddress);\nif (existingUser) {\n    user = existingUser;                 // \u003c-- links to the EXISTING account, by email alone\n} else {\n    user = new User({ identifier: config.emailAddress, verified: config.verified || false, ... });\n}\nconst authMethod = await this.connection.getRepository(ctx, ExternalAuthenticationMethod).save(\n    new ExternalAuthenticationMethod({ externalIdentifier: config.externalIdentifier, strategy: config.strategy }),\n);\nuser.authenticationMethods = [...(user.authenticationMethods || []), authMethod];   // \u003c-- external login attached\nawait this.connection.getRepository(ctx, User).save(user);\n```\n`config.verified` is used only to set `User.verified` and to write a `CUSTOMER_VERIFIED` history entry (later in the method) — it is **never** used to gate whether the external method may be attached to an existing account. So an unverified external email links to the victim's account just the same.\n\n## Impact\nAccount takeover of any customer whose email address an attacker can present (unverified) via an external auth provider — read/modify the victim's orders, addresses, and PII, and place orders as them. The blast radius depends on the deployed `AuthenticationStrategy`(ies): strategies that don't strictly require a provider-verified email (or providers that don't guarantee email ownership) are directly exploitable.\n\n## Reproduction (conceptual)\n1. Victim has a native Vendure customer account `victim@example.com`.\n2. Attacker authenticates through an external provider configured on the store, presenting `emailAddress = victim@example.com` with `verified` unset/false (depending on the strategy/provider).\n3. `createCustomerAndUser` finds the victim's existing User by email and attaches the attacker's `ExternalAuthenticationMethod`.\n4. Attacker logs in via that external method → authenticated as the victim.\n\n## Suggested fix\nRefuse to bind an external authentication method to a **pre-existing** account unless the email is provably verified, and prefer explicit, authenticated account-linking:\n```ts\nif (existingUser) {\n    if (!config.verified) {\n        // Do not silently link an unverified external identity to an existing account.\n        throw new EmailAddressConflictError(); // or require the user to link while logged in\n    }\n    user = existingUser;\n}\n```\nDocument clearly that an `AuthenticationStrategy` MUST only set `verified: true` for provider-verified emails, and that linking to existing accounts requires it.","aliases":["CVE-2026-63472"],"modified":"2026-09-17T15:00:06.681857527Z","published":"2026-09-17T14:50:22Z","database_specific":{"cwe_ids":["CWE-287"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-09-17T14:50:22Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/vendurehq/vendure/security/advisories/GHSA-6j36-r6pr-59x4"},{"type":"WEB","url":"https://github.com/vendurehq/vendure/commit/3bb04718ea4f9395fda731bd2a4bcfc3afb0a485"},{"type":"PACKAGE","url":"https://github.com/vendurehq/vendure"},{"type":"WEB","url":"https://github.com/vendurehq/vendure/releases/tag/v3.7.0"}],"affected":[{"package":{"name":"@vendure/core","ecosystem":"npm","purl":"pkg:npm/%40vendure/core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.7.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-6j36-r6pr-59x4/GHSA-6j36-r6pr-59x4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}