Intel

AIKIDO-2025-10823

@capgo/capacitor-social-login is vulnerable to Authentication Bypass by Capture-replay

Authentication Bypass by Capture-replay Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Nov 19, 2025

68

Medium Risk

This Affects:

JS@capgo/capacitor-social-login
0.0.1 - 7.17.0
Fixed in 7.18.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to replay attacks due to insufficient nonce implementation in the Google sign-in flow. Without proper nonce validation, an attacker could intercept authentication tokens during transmission and reuse them to impersonate legitimate users. It could allow unauthorized access to user accounts and associated data. The vulnerability exists because the nonce parameter is not properly generated or validated.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and if you using the Google sign-in flow.

Background info

@capgo/capacitor-social-login is vulnerable to Authentication Bypass by Capture-replay in versions 0.0.1 - 7.17.0.

How to fix this

Upgrade the @capgo/capacitor-social-login library to the patch version.