Description
An open redirect vulnerability exists in AuthService.handleCallback due to insufficient validation of the returnPathname value derived from the OAuth state parameter.
The state parameter is round-tripped through the identity provider (IdP) and can be influenced by an attacker.
Recommendation
Update the @workos/authkit-session package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.5.1
- Patched version(s): 0.5.1
References
Could your website be exposed too?
SmartScanner can check your website for @workos/authkit-session has an Open Redirect via state-derived redirect target and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Waku has an Open Redirect via `unstable_redirect` Helper - CVE-2026-49456
- Nitro has an Open Redirect via Protocol-Relative URL Bypass in Wildcard Route Rules - CVE-2026-44372
- Nitro has an Open Redirect via Protocol-Relative URL Bypass in Wildcard Route Rules - nitro - CVE-2026-44372
- Feathers has an open redirect in OAuth callback enables account takeover - CVE-2026-27191


