THREAT OPS › Threat News › [GHSA] GHSA-6j36-r6pr-59x4 (critical) — Vendure affected by external-authentication account takeover: external login linked to a pre-existing account by email without verification
[GHSA] GHSA-6j36-r6pr-59x4 (critical) — Vendure affected by external-authentication account takeover: external login linked to a pre-existing account by email without verification
GHSA-6j36-r6pr-59x4 Severity: critical CVE: CVE-2026-63472
Vendure affected by external-authentication account takeover: external login linked to a pre-existing account by email without verification
# External-authentication account takeover: external login linked to a pre-existing account by email without requiring verification
**Package:** @vendure/core (vendure-ecommerce/vendure, latest mast
Indicators of compromise
- CVE-2026-63472cve
Original source: https://github.com/advisories/GHSA-6j36-r6pr-59x4