Vulnerability GO-2026-5548
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
2 months ago
July 24, 2026 at 06:35 PM UTC
PocketBase: Account pre-hijacking via OAuth2 autolinking upgrade in github.com/pocketbase/pocketbase
v0.1.0 - v0.22.41
v0.1.0 - v0.22.41
Summary
PocketBase: Account pre-hijacking via OAuth2 autolinking upgrade in github.com/pocketbase/pocketbase
Details
PocketBase: Account pre-hijacking via OAuth2 autolinking upgrade in github.com/pocketbase/pocketbase
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
20 days ago
Pocketbase: Unhandled panic in worker goroutines
v0.1.0 - v0.22.47 and v0.23.0 - v0.39.6 GHSA-84vh-m24q-wjjx
v0.1.0 - v0.22.47 and v0.23.0 - v0.39.6 GHSA-84vh-m24q-wjjx
Medium Risk
5 months ago
PocketBase vulnerable to account pre-hijacking via OAuth2 unverfied->verified autolinking upgrade
v0.1.0 - v0.22.41 and v0.30.0 - v0.37.3 GHSA-pq7p-mc74-g65w
v0.1.0 - v0.22.41 and v0.30.0 - v0.37.3 GHSA-pq7p-mc74-g65w
Unknown
2 years ago
PocketBase performs password auth and OAuth2 unverified email linking in github.com/pocketbase/pocketbase
v0.1.0 - v0.22.14-rc GO-2024-2936
v0.1.0 - v0.22.14-rc GO-2024-2936
Medium Risk
2 years ago
PocketBase performs password auth and OAuth2 unverified email linking
v0.1.0 - v0.22.14-rc GHSA-m93w-4fxv-r35v
v0.1.0 - v0.22.14-rc GHSA-m93w-4fxv-r35v
Impacted packages
Timeline
Published
2 months ago
July 24, 2026 at 06:35 PM UTC
Last Modified
2 months ago
July 24, 2026 at 07:00 PM UTC