OSV 1.4.0 · github-reviewed · 修改于 2026-07-07 21:01
发布时间
2026-07-07 21:01
GitHub 审查时间
2026-07-07 21:01
NVD 发布时间
—
源文件
advisories/github-reviewed/2026/07/GHSA-26v7-h57m-gh9m/GHSA-26v7-h57m-gh9m.json
The email and WeChat account binding endpoints used GET requests for state-changing account operations. In deployments where session cookies could be sent on cross-site navigations, an attacker could trigger a logged-in user's browser to bind an attacker-controlled email address or OAuth identity.
Affected endpoints included:
GET /api/oauth/email/bindGET /api/oauth/wechat/bindA successful attack could change account binding state. For email binding, the attacker could bind an email address they control and then attempt follow-on account recovery flows. The default session cookie configuration uses SameSite=Strict, which mitigates common cross-site navigation attacks in modern browsers, so the issue is rated Medium.
Versions before v0.12.0-alpha.1 are affected.
This issue is fixed in v0.12.0-alpha.1. The fix changes email and WeChat binding routes from GET to POST and reads parameters from a JSON request body instead of query parameters. The same change set also normalizes password reset responses to avoid disclosing whether an email is registered.
If upgrading immediately is not possible, ensure session cookies are configured with strict SameSite behavior and block GET requests to /api/oauth/email/bind and /api/oauth/wechat/bind at the reverse proxy.
e099117c61391abdf888fb75e382a582e550bd0e.router/api-router.go and controller/user.go.