@capgo/capacitor-social-login is vulnerable to Authentication Bypass by Capture-replay
68
Medium Risk
Affected versions of this package are vulnerable to replay attacks due to insufficient nonce implementation in the Google sign-in flow. Without proper nonce validation, an attacker could intercept authentication tokens during transmission and reuse them to impersonate legitimate users. It could allow unauthorized access to user accounts and associated data. The vulnerability exists because the nonce parameter is not properly generated or validated.
You are affected if you are using a version that falls within the vulnerable range and if you using the Google sign-in flow.
@capgo/capacitor-social-login is vulnerable to Authentication Bypass by Capture-replay in versions 0.0.1 - 7.17.0.
Upgrade the @capgo/capacitor-social-login library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant