SCA: security update for @auth/core, next-auth (GHSA-x445-f3h2-j279)

medium Tenable Self-Hosted Container Security Plugin ID 445219

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and
5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, nonce, and the PKCE verifier in
global cookies that are not bound to the provider that created them. On callback, a check value minted
during a sign-in started with one provider can satisfy the callback for a different provider because the
stored cookie is not verified against the callback provider's identity, including the provider ID, issuer,
client ID, or redirect URI. In a multi-provider application that permits account linking while logged in,
when one provider's authorization request is observable and a target provider callback can be satisfied
without a PKCE verifier, an attacker can lure a victim into starting a legitimate same-origin flow and
link the attacker's target-provider account to the victim's Auth.js user. The linked provider grants the
attacker persistent sign-in to the victim's account, while cross-site request forgery alone is
insufficient. This issue is fixed in @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32.
(CVE-2026-73419)

Solution

Update the @auth/core library and its related packages to version 0.41.3 or later.

See Also

https://github.com/advisories/GHSA-x445-f3h2-j279

Plugin Details

Severity: Medium

ID: 445219

Version: Revision 1.2

Type: Local

Family: SCA Checks

Published: 7/23/2026

Updated: 8/13/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: High

Base Score: 7.1

Temporal Score: 5.3

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2026-73419

CVSS v3

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.9

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 7/23/2026

Vulnerability Publication Date: 7/23/2026

Reference Information

CVE: CVE-2026-73419