Reflected Cross-Site Scripting Vulnerability in AshAuthentication by Team Alembic
CVE-2026-66882
What is CVE-2026-66882?
A vulnerability exists in Team Alembic's AshAuthentication due to improper neutralization of input during web page generation. This reflected XSS issue allows attackers to inject arbitrary scripts via manipulated URLs, affecting users interacting with authentication confirmation and magic link forms. Attackers can exploit the lack of input validation and HTML escaping in the generated HTML pages, which directly embed user-supplied parameters, leading to unauthorized access to session cookies and other sensitive data. This vulnerability impacts specific versions of AshAuthentication, making it critical for users to update to secure versions.
Affected Version(s)
ash_authentication 4.8.0 < 4.14.2
ash_authentication 5.0.0-rc.0 < 5.0.0-rc.13
ash_authentication fe0b4558dbe852fee5d81a460a8355577618a8c8
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
