CVE-2026-108157
Pingvin Share X 0.19.0 before 1.22.0 Account Takeover via OAuth Email Linking
CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th
Pingvin Share X from 0.19.0 before 1.22.0 contains an improper authentication vulnerability that allows remote unauthenticated attackers to take over accounts by abusing automatic OAuth email linking in OAuthService.signUp(). Attackers can register a victim's unverified email on an enabled OAuth/OIDC provider, exploiting the missing email_verified check in GenericOidcProvider, to sign in as the victim including administrators while bypassing TOTP.
| CWE | CWE-287 |
| Vendor | smp46 |
| Product | pingvin-share-x |
| Published | Oct 9, 2026 |
| Last Updated | Oct 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for smp46 pingvin-share-x
Be the first to know when new high vulnerabilities affecting smp46 pingvin-share-x are published β delivered to Slack, Telegram or Discord.
Get Free Alerts β
Free Β· No credit card Β· 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
smp46 / pingvin-share-x
0.19.0 < 1.22.0
References
github.com: https://github.com/smp46/pingvin-share-x/security/advisories/GHSA-wrcg-4874-45p7 github.com: https://github.com/smp46/pingvin-share-x/commit/07aa8c0a96030c439e9018ce94a2778bd37304e6 github.com: https://github.com/smp46/pingvin-share-x/blob/de7ffecf9bfc4976993149a5c4c98efe35161424/backend/src/oauth/oauth.service.ts#L158-L175 github.com: https://github.com/smp46/pingvin-share-x/releases/tag/v1.22.0 github.com: https://github.com/smp46/pingvin-share-x vulncheck.com: https://www.vulncheck.com/advisories/pingvin-share-x-0.19.0-before-1.22.0-account-takeover-via-oauth-email-linking
Credits
MatΓ©o Florian Callec