Threat Advisory

OAuth State Check Fails Open on Omitted State

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium-severity vulnerability affecting @hono/oauth-providers versions < 0.8.6, identified as CVE-2026-81888 with a CVSS score of 5.4, exists in the OAuth state check mechanism of @hono/oauth-providers version 0.8.5 or earlier. This flaw enables login CSRF and forced account linking through affected social media providers including Google, GitHub, Facebook, Discord, Twitch, LinkedIn, and MSentra when an attacker exploits the omission of the state value during the OAuth callback process. The vulnerability arises from the built-in social login providers accepting an OAuth callback even when the state value is absent on both sides, thereby defeating the state-based CSRF protection under default usage. An attacker can manipulate a victim's browser to complete an OAuth callback that binds their identity instead of the victim's, leading to potential security risks such as login CSRF or forced account linking in applications utilizing affected providers on @hono/oauth-providers.

RECOMMENDATION:

We recommend you to update @hono/oauth-providers to version 0.8.6.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium-severity vulnerability affecting @hono/oauth-providers versions < 0.8.6, identified as CVE-2026-81888 with a CVSS score of 5.4, exists in the OAuth state check mechanism of @hono/oauth-providers version 0.8.5 or earlier. This flaw enables login CSRF and forced account linking through affected social media providers including Google, GitHub, Facebook, Discord, Twitch, LinkedIn, and MSentra when an attacker exploits the omission of the state value during the OAuth callback process. The vulnerability arises from the built-in social login providers accepting an OAuth callback even when the state value is absent on both sides, thereby defeating the state-based CSRF protection under default usage. An attacker can manipulate a victim's browser to complete an OAuth callback that binds their identity instead of the victim's, leading to potential security risks such as login CSRF or forced account linking in applications utilizing affected providers on @hono/oauth-providers.

RECOMMENDATION:

We recommend you to update @hono/oauth-providers to version 0.8.6.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu