Hall of Fame trophy
Back to Hall of Fame Contents

Contents / ClaimBleed

OIDC access-token identity overwrite

GHSA-xwv8-m73h-68vg was reported by crypto-nidh.

An administrator-configured OIDC claim whitelist could copy attacker-controlled access-token claims over the trusted userinfo id, username, email and other service-owned fields, potentially linking the attacker's login to a victim account.

Fix: whitelisted claims can add only non-reserved metadata. Identity, token, group and object-prototype fields remain owned by WeKan and trusted userinfo. No Problems event is emitted because legitimate OIDC logins use the same path. Fixed in the upcoming WeKan release on 2026-08-26.