Vulnerabilities/

@workos/authkit-session has an Open Redirect via state-derived redirect target

Severity:
Medium

Description

An open redirect vulnerability exists in AuthService.handleCallback due to insufficient validation of the returnPathname value derived from the OAuth state parameter.

The state parameter is round-tripped through the identity provider (IdP) and can be influenced by an attacker.

Recommendation

Update the @workos/authkit-session package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@workos/authkit-session
Anything's wrong? Let us know Last updated on May 13, 2026