@hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.4epss 0.1%
probabilidad de explotación
0.1%top 96% de las CVE
explotación observada
noninguna fuente lo reporta
@hono/oauth-providers is Authentication middleware for Hono. Prior to version 0.8.6, the built-in social login providers accept an OAuth callback even when the `state` value is absent on both sides, so the anti-CSRF check passes for a callback that never came from a genuine login attempt. This defeats the `state`-based CSRF protection under default usage. Version 0.8.6 has a patch.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Productos afectados
honojs · @hono/oauth-providersReferencias
https://github.com/honojs/middleware/commit/b37765f40b7bddb1d8fce39573b085222dea58c1https://github.com/honojs/middleware/pull/2040https://github.com/honojs/middleware/releases/tag/%40hono%2Foauth-providers%400.8.6https://github.com/honojs/middleware/security/advisories/GHSA-fm3f-ch8h-qw8q