vulns.co
/
GKData.io MCP

Nhost · 1 min read

Nhost: provider adapters must preserve identity-claim evidence

CVE-2026-41574 describes provider adapters converting email presence or fallback profile attributes into a verification claim. An account-linking consumer then treated that normalized claim as ownership evidence. The maintainer reports unauthorized identity merging and authenticated access to an existing account.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

Editorial reasoning: normalization must retain the strength and origin of evidence. A nonempty identity attribute is not interchangeable with proof of mailbox control. Review adapter contracts and the account-linking decision together; rejecting absent or unverified evidence must remain consistent across providers. Official auth@0.49.1 release notes dated 2026-04-17 corroborate stricter provider email-verification handling.

Before reading

  • OAuth identity-provider claims and local account-linking concepts

Context and limits

  • The advisory lists auth service versions before 0.49.1 as affected. Exposure depends on an affected provider adapter being enabled and an existing matching local identity. Provider-specific prerequisites differ; no universal OAuth-provider compromise is established.
  • dbarrosop published the advisory; skoveit is credited as reporter. Technical claims are maintainer-reported, not independently reproduced.
  • The advisory makes provider-specific assertions about Microsoft claims that were not independently corroborated; this record relies on the broader adapter-evidence boundary, not those assertions.
  • Maintainer disclosure, not a peer-reviewed paper or an award-backed report. Software patch chronology is separate from resource edition metadata.

Sources and provenance

  1. Account Takeover via OAuth Email Verification Bypass Nhost · reviewed 2026-10-03
  2. Release auth@0.49.1 Nhost · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software