CVE-2026-22694

Source
https://cve.org/CVERecord?id=CVE-2026-22694
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22694.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-22694
Aliases
  • GHSA-mvg4-wvjv-332q
Published
2026-01-14T16:32:36.007Z
Modified
2026-03-01T02:56:16.955019Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N CVSS Calculator
Summary
AliasVault is Missing Origin Validation in Android Passkey Credential Provider
Details

AliasVault is a privacy-first password manager with built-in email aliasing. AliasVault Android versions 0.24.0 through 0.25.2 contained an issue in how passkey requests from Android apps were validated. Under certain local conditions, a malicious app could attempt to obtain a passkey response for a site it was not authorized to access. The issue involved incomplete validation of calling app identity, origin, and RP ID in the Android credential provider. This issue was fixed in AliasVault Android 0.25.3.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-346"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22694.json"
}
References

Affected packages

Git / github.com/aliasvault/aliasvault

Affected ranges

Type
GIT
Repo
https://github.com/aliasvault/aliasvault
Events

Affected versions

0.*
0.24.0
0.25.0
0.25.1
0.25.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22694.json"