Intel

AIKIDO-2026-10150

@feathersjs/authentication-oauth is vulnerable to Improper Input Validation

Improper Input Validation Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Feb 10, 2026

72

High Risk

This Affects:

JS@feathersjs/authentication-oauth
5.0.0 - 5.0.39
Fixed in 5.0.40
Are you affected? Scan for Free

TL;DR

Affected versions of this package were vulnerable to improper URL and origin validation, enabling a generic OAuth redirection abuse issue. An attacker could manipulate unvalidated or weakly validated redirect/origin values to force the application to redirect sensitive OAuth responses (such as access tokens) to attacker-controlled endpoints, including look-alike or crafted URLs that bypass origin checks, resulting in token leakage and unauthorized account access.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@feathersjs/authentication-oauth is vulnerable to Improper Input Validation in versions 5.0.0 - 5.0.39.

How to fix this

Upgrade the @feathersjs/authentication-oauth library to the patch version.