A vulnerability described as problematic has been identified in nextauthjs next-auth and core. Affected by this vulnerability is an unknown functionality of the component OAuth/OIDC Anti-CSRF Check. The manipulation results in cross-site request forgery.

This vulnerability was named CVE-2026-73419. The attack may be performed from remote. There is no available exploit.