GHSA-fm3f-ch8h-qw8q
MODERATECVE-2026-81888The built-in social login providers accept an OAuth callback even when the state value is absent on both sides, so the anti-CSRF check passes for a callback that never came from a genuine login attempt. This defeats the state-based CSRF protection under default usage.
- Affected
- >=0, <0.8.6, < 0.8.6
- Fixed in
- 0.8.6
- Weakness
- CWE-352
- Published
- 2026-08-31
- Source
- osv