Intent-Code Divergence
High
- Confidence
- 98% confidence
- Finding
- The account-linking example links an OAuth identity to an existing local account based only on email equality, while later treating provider email as implicitly verified. This is dangerous because some providers may return unverified or weakly verified email claims, allowing account takeover if an attacker authenticates with a provider account that presents the victim’s email address.
