← voltar
CVE-2026-81888mediumCWE-1275CWE-352

@hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking

13Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 5.4epss 0.1%
probabilidade de exploração
0.1%top 96% das CVEs
exploração observada
nãonenhuma fonte reporta
@hono/oauth-providers is Authentication middleware for Hono. Prior to version 0.8.6, the built-in social login providers accept an OAuth callback even when the `state` value is absent on both sides, so the anti-CSRF check passes for a callback that never came from a genuine login attempt. This defeats the `state`-based CSRF protection under default usage. Version 0.8.6 has a patch.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N