GHSA-7p7c-6qwr-q8j7CriticalCVSS 8.1

Pingvin Share X from 0.19.0 before 1.22.0 contains an improper authentication vulnerability that...

Published
October 9, 2026
Last Modified
October 9, 2026

🔗 CVE IDs covered (1)

📋 Description

Pingvin Share X from 0.19.0 before 1.22.0 contains an improper authentication vulnerability that allows remote unauthenticated attackers to take over accounts by abusing automatic OAuth email linking in OAuthService.signUp(). Attackers can register a victim's unverified email on an enabled OAuth/OIDC provider, exploiting the missing email_verified check in GenericOidcProvider, to sign in as the victim including administrators while bypassing TOTP.

🔗 References (8)