CVE Explorer
CVE-2026-31813
Supabase Auth is a JWT based API for managing users and issuing JWT tokens. Prior to 2.185.0, a vulnerability has been identified that allows an attacker to issue sessions for arbitrary users using specially crafted ID tokens when the Apple or Azure providers are enabled. The attacker issues a valid, asymmetrically signed ID token from their issuer for each victim email address, which then is sent to the Supabase Auth token endpoint using the ID token flow. If the ID token is OIDC compliant, the
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"auth","vendor":"supabase","versions":[{"status":"affected","version":"< 2.185.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:384666c67cb54d2d9026e883c51ddae807b946fe12dc09e51cc147826f300d00 · sha256:ad0c9ee584f4f4e6… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:384666c67cb54d2d9026e883c51ddae807b946fe12dc09e51cc147826f300d00 · sha256:ad0c9ee584f4f4e6… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-290","description":"CWE-290: Authentication Bypass by Spoofing","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:384666c67cb54d2d9026e883c51ddae807b946fe12dc09e51cc147826f300d00 · sha256:ad0c9ee584f4f4e6… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/supabase/auth/security/advisories/GHSA-v36f-qvww-8w8m","tags":["x_refsource_CONFIRM"],"url":"https://github.com/supabase/auth/security/advisories/GHSA-v36f-qvww-8w8m"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:384666c67cb54d2d9026e883c51ddae807b946fe12dc09e51cc147826f300d00 · sha256:ad0c9ee584f4f4e6… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.