THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-6j36-r6pr-59x4 (critical) — Vendure affected by external-authentication account takeover: external login linked to a pre-existing account by email without verification

[GHSA] GHSA-6j36-r6pr-59x4 (critical) — Vendure affected by external-authentication account takeover: external login linked to a pre-existing account by email without verification

medgithub_advisoriesPublished 2026-09-17

GHSA-6j36-r6pr-59x4 Severity: critical CVE: CVE-2026-63472

Vendure affected by external-authentication account takeover: external login linked to a pre-existing account by email without verification

# External-authentication account takeover: external login linked to a pre-existing account by email without requiring verification

**Package:** @vendure/core (vendure-ecommerce/vendure, latest mast

Indicators of compromise

Original source: https://github.com/advisories/GHSA-6j36-r6pr-59x4