Intel

AIKIDO-2025-10627

angular-auth-oidc-client is vulnerable to Origin Validation Error

Origin Validation Error Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Sep 10, 2025

20

Low Risk

This Affects:

JSangular-auth-oidc-client
11.6.0 - 19.0.2
Fixed in 20.0.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to OpenID Connect Issuer Validation Bypass due to a missing validation of the issuer field in the discovered OpenID Configuration document against the expected authority URL. An attacker could exploit this by poisoning a reverse proxy cache or via a man-in-the-middle attack to redirect discovery requests to a malicious domain, which would then supply a fraudulent configuration document with a matching issuer.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

angular-auth-oidc-client is vulnerable to Origin Validation Error in versions 11.6.0 - 19.0.2.

How to fix this

Upgrade the angular-auth-oidc-client library to the patch version.