Skip to content
← archivevulnerability · 25 Sep 2026 · 15:55 UTC

GHSA-g7vj-c29h-3h5m: FriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email trust in Discord OAuth provider

VULNCVE-2026-92161source · GTH
HIGHCritical vulnerability — CVSS 9.8
What to do
  • Critical severity — schedule an urgent patch.

last 60 dispatches · spectrum

### Impact An unauthenticated account takeover vulnerability exists in `fof/oauth` when the Discord OAuth provider is enabled. Discord allows an account to use an unverified email address when its phone number has been verified. During OAuth authentication, Discord may return that email address with `"verified": false`. Affected versions of `fof/oauth` did not validate this flag and passed the email address to Flarum core as trusted via `provideTrustedEmail()`. …

grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected