Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability exists in the authentication system, specifically concerning the use of magic links. This issue allows an attacker with a compromised magic link to authenticate as another user due to a race condition in how the link's single-use token is validated and consumed. The primary concern is to confirm if this authentication technology is in use and assess potential exposure.
- Replay of single-use magic links.
- Confirms potential exposure of authentication technology.
- Verify if magic links are used in your environment.
Attack Path
How an attacker could exploit the issue
An attacker with a previously leaked magic link can exploit a race condition to bypass authentication. By quickly replaying the single-use token from the magic link before it's revoked, an attacker can successfully sign in as the intended user. This vulnerability arises because the system checks the token's validity and revokes it after the sign-in process has already completed, allowing multiple concurrent attempts with the same token to succeed.
- Leaked magic link is required.
- Race condition during token redemption.
- Unauthorized account access.
Live Threat
Current exploitation, exposure, and threat context
A Time-of-check Time-of-use (TOCTOU) race condition vulnerability in AshAuthentication allows an attacker with a leaked magic link to replay its single-use token and authenticate as the target user. This occurs because the system checks the token's validity and then consumes it in separate steps, creating a small window where concurrent requests can all succeed. When supported by the advisory, this could affect user account access and session tokens.
- User account access and session tokens.
- Concurrent requests to replay tokens.
- Unauthorized account access and session hijack.
Operational Fix
Recommended remediation, mitigation, and detection steps
The critical time-of-check to time-of-use (TOCTOU) race condition in AshAuthentication's magic link handling can allow an attacker with a leaked token to impersonate users. Teams responsible for identity and access management, application platforms, or critical user-facing services should prioritize identifying all instances of the affected authentication components, assessing their exposure, and planning for remediation. The immediate first step involves locating the technology, confirming its reachability and business criticality, and identifying the accountable owner to develop a risk-based remediation plan.
- Application or platform owners should own the issue.
- Verify if magic link sign-in is in use.
- Plan remediation based on identified risk.