
Supabase auth (pre-2.185.0) accepted oidc tokens from attacker-controlled issuers if the signature was valid. CVE-2026-31813 Real test: do you verify the issuer matches the expected provider, or only that the jwt signature is valid? Those are different checks.
Post summary
The post discloses that Supabase auth versions before 2.185.0 accept OIDC tokens from attacker-controlled issuers when only the JWT signature is verified, but it does not provide an exploit, patch, or evidence of active exploitation.


