@chat-adapter/gchat is vulnerable to Authentication Bypass
59
Medium Risk
The Google Chat adapter verifies incoming webhook and Pub/Sub JWTs but accepts tokens with generic identity shapes or public audiences rather than binding them to the configured service identity. A request bearing any suitably shaped Google-issued token can therefore be accepted as an authentic Google Chat event. This lets externally supplied requests impersonate the platform and drive the bot with forged messages and events. The fix binds endpoint and Pub/Sub tokens to the configured, verified service identities before a request is trusted.
You are affected if you are using a version that falls within the vulnerable range and you use the Google Chat adapter to verify incoming direct webhook or Pub/Sub requests.
@chat-adapter/gchat is vulnerable to Authentication Bypass in versions 4.21.0 - 4.36.0.
Upgrade the @chat-adapter/gchat library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant