Intel

AIKIDO-2025-10601

kovah/laravel-socialite-oidc is vulnerable to Replay Attacks

Replay Attacks Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Sep 2, 2025

67

Medium Risk

This Affects:

PHPkovah/laravel-socialite-oidc
0.1.0 - 0.4.0
Fixed in 0.5.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to replay attacks because the nonce remains in the session after successful validation, allowing attackers to reuse it to bypass authentication or authorization checks.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

kovah/laravel-socialite-oidc is vulnerable to Replay Attacks in versions 0.1.0 - 0.4.0.

How to fix this

Upgrade the kovah/laravel-socialite-oidc library to the patch version.