Description
A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the “Expo AuthSession Redirect Proxy” for social sign-in. This can be achieved once a victim clicks a malicious link.
Recommendation
Update the expo package to the latest compatible version. Followings are version details:
- Affected version(s): < 48.0.0
- Patched version(s): 48.0.0
References
Could your website be exposed too?
SmartScanner can check your website for Expo SDK has an OAuth vulnerability and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Vega has Cross-site Scripting vulnerability in `lassoAppend` function - vega - CVE-2023-26487
- BSV Blockchain SDK has an Authentication Signature Data Preparation Vulnerability - CVE-2025-69287
- Vega has Cross-site Scripting vulnerability in `lassoAppend` function - CVE-2023-26487
- Gatsby develop server has Local File Inclusion vulnerability - CVE-2023-34238


