GHSA-g7vj-c29h-3h5m: FriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email trust in Discord OAuth provider
HIGHCritical vulnerability — CVSS 9.8
What to do
- Critical severity — schedule an urgent patch.
### Impact An unauthenticated account takeover vulnerability exists in `fof/oauth` when the Discord OAuth provider is enabled. Discord allows an account to use an unverified email address when its phone number has been verified. During OAuth authentication, Discord may return that email address with `"verified": false`. Affected versions of `fof/oauth` did not validate this flag and passed the email address to Flarum core as trusted via `provideTrustedEmail()`. …
CVE · detail
Early access
Get the next one first.
Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.
bot-protected