Ory logo

Impersonating users by abusing broken “Sign in with” implementations

Several applications implementing “Sign in with GitHub” have been found to be using a mutable identifier (username) to match external users to the internal user management system. This allows attackers to completely take over accounts whose GitHub username has changed.

Further reading

<- Back to Blog