---
id: GO-2026-6216
title: Cross-forge account takeover on login in codefloe.com/crowci/crow/v6
summary: Cross-forge account takeover on login in codefloe.com/crowci/crow/v6
severity: none
vendor: crowci
product: codefloe.com/crowci/crow/v6
ecosystem: go
affected:
  - codefloe.com/crowci/crow/v6 < 6.4.0
patched:
  - codefloe.com/crowci/crow/v6 6.4.0
published: '2026-08-18'
updated: '2026-08-18'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GO-2026-6216'
references:
  - url: >-
      https://codefloe.com/crowci/crow/src/branch/main/security/advisories/cross-forge-account-takeover.md
  - url: >-
      https://codefloe.com/crowci/crow/commit/6b4405f1ef0126e5074383e551ae38d55c2a7efe
  - url: 'https://codefloe.com/crowci/crow/releases/tag/v6.4.0'
tags:
  - osv
  - go
ingestedAt: '2026-08-19T19:22:26.615Z'
---

## Overview

In codefloe.com/crowci/crow/v6 before 6.4.0, user account lookup during forge login is not scoped to the authenticating forge. An account on one forge matches an existing user on another forge via forge remote ID collision or username collision. On instances with multiple configured forges, an attacker can take over arbitrary Crow accounts by registering matching credentials on any connected forge.

## Affected packages

- `codefloe.com/crowci/crow/v6 < 6.4.0`

## Remediation

Upgrade to a patched release:

- `codefloe.com/crowci/crow/v6 6.4.0`
