authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow Executor) in order to make the interface more compatible with legacy browsers, it was possible to use an XSS exploit in the AutosubmitStage. This issue has been patched in versions 2025.12.5 and 2026.2.3.
The vulnerability stems from the way stages are implemented in the SFE mechanism, which was designed to ensure compatibility with legacy browsers. Insufficient data sanitization in the AutosubmitStage component allows injection and execution of malicious JavaScript code in the context of the application. The attack requires user interaction (UI:R), but does not require any authentication or special privileges on the attacker's side, and its effects may extend beyond the source domain (S:C — scope change).
An attacker can gain access to sensitive user data (e.g., sessions, tokens) and perform unauthorized modifications in the context of a logged-in user, which in the case of an identity management system can lead to account takeover or unauthorized access to protected resources.
Goauthentik Authentik should be updated to version 2025.12.5 or 2026.2.3 (or newer), in which the vulnerability has been fixed. Details are available in the vendor's references: https://github.com/goauthentik/authentik/security/advisories/GHSA-pgff-5mx8-fqj3
Goauthentik Authentik in versions prior to 2025.12.5 and prior to 2026.2.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NGoauthentik Authentik
APPGoauthentik< 2025.12.52026.2.0 – 2026.2.3 (excl.)
Related vulnerabilities
Pominięcie etapu uwierzytelniania (Source Stage) w Goauthentik Authentik
RCE w authentik przez endpoint testowy mapowania właściwości
Pominięcie uwierzytelnienia przez nagłówek X-Forwarded-For w authentik
authentik — pominięcie uwierzytelnienia przy resetowaniu hasła admina
Authentik: przejęcie konta przez nieprawidłową walidację tokenu odzyskiwania