OpenID Connect Authentication Extension Vulnerability in TYPO3
CVE-2025-24856
What is CVE-2025-24856?
A vulnerability has been identified in the OpenID Connect Authentication extension for TYPO3, prior to version 4.0.0. This defect in the account linking logic could potentially allow an attacker to exploit conditions for a pre-hijacking attack, which might lead to unauthorized account takeover. The attack requires the malicious actor to predict a user's email address and create a public frontend user account using that address before the user's initial login via OIDC. Additionally, this condition is exacerbated if the Identity Provider (IDP) returns the user's email address in the authentication response.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
oidc 0 < 4.0.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
