remix-auth-oauth2 is vulnerable to Cross-Site Request Forgery (CSRF)
30
Low Risk
Affected versions of the package are vulnerable to Cross-site Request Forgery (CSRF) attacks due to improper validation of the state URL parameter. Without proper validation, attackers could exploit this flaw for CSRF or impersonation attacks. Similar issues have previously enabled phishing attempts by manipulating error messages. In recent updates, remix-auth-oauth2 moved state management from session storage to cookies, requiring earlier validation in the handler. This patch ensures that only legitimate OAuth2 requests proceed while unauthorized attempts trigger a generic error page.
You are affected if you are using a version that falls within the vulnerable range.
remix-auth-oauth2 is vulnerable to Cross-Site Request Forgery (CSRF) in versions 3.0.0 - 3.2.2.
Upgrade the remix-auth-oauth2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant