Intel

AIKIDO-2026-459118

@vendure/core is vulnerable to Improper Authentication

Improper AuthenticationGHSA-wr5h-x3x6-4h23 Published Today

93

Critical Risk

This Affects:

JS@vendure/core
1.5.0 - 3.7.2
Fixed in 3.7.3
Are you affected? Scan for Free

TL;DR

The Shop API registerCustomerAccount mutation creates native (password) credentials for an email address without confirming that the caller owns that address, even when the address already belongs to an external or SSO-only customer. An unauthenticated actor can register an existing SSO customer's email with a chosen password and then log in natively, taking over the account. The fix requires email verification before native credentials become active for a pre-existing external-auth account.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you allow customers to register accounts alongside an external or SSO login strategy.

Background info

@vendure/core is vulnerable to Improper Authentication in versions 1.5.0 - 3.7.2.

How to fix this

Upgrade the @vendure/core library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform