CVE-2026-66882 | team-alembic ash_authentication up to 4.14.1/5.0.0-rc.12 Confirmation Form confirmation_form.html.eex confirm cross site scripting
A vulnerability was found in team-alembic ash_authentication up to 4.14.1/5.0.0-rc.12. It has been classified as problematic. This issue affects the function AshAuthentication.AddOn.Confirmation.Plug.accept/AshAuthentication.Strategy.MagicLink.Plug.accept of the file lib/ash_authentication/add_ons/confirmation/confirmation_form.html.eex of the component Confirmation Form. Performing a manipulation of the argument confirm results in cross site scripting.
This vulnerability is cataloged as CVE-2026-66882. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More