oAuth 1 and 2 authentication for Feathers. Powered by Grant.
90%
Total Score
100
100
100
100
50
| Title | Versions | Severity |
|---|---|---|
CVE-2026-29792 @feathersjs/authentication-oauth is vulnerable to Improper Authentication in versions 5.0.0 - 5.0.41. | 5.0.0 - 5.0.41 | Critical |
AIKIDO-2026-10204 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @feathersjs/authentication-oauth is vulnerable to Open Redirect in versions 4.0.0 - 4.5.18. | 4.0.0 - 4.5.18 | Medium |
CVE-2026-27193 @feathersjs/authentication-oauth is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.0 - 5.0.39. | 0.0.0 - 5.0.39 | High |
CVE-2026-27192 @feathersjs/authentication-oauth is vulnerable to Origin Validation Error in versions 0.0.0 - 5.0.39. | 0.0.0 - 5.0.39 | High |
CVE-2026-27191 @feathersjs/authentication-oauth is vulnerable to URL Redirection to Untrusted Site ('Open Redirect') in versions 0.0.0 - 5.0.39. | 0.0.0 - 5.0.39 | High |
| Dependency | Last Release | Score |
|---|---|---|
qs Version ^6.15.0 | — | — |
grant Version ^5.4.24 | — | — |
koa-session Version ^7.0.2 | — | — |
cookie-session Version ^2.1.1 | — | — |
@feathersjs/koa Version ^5.0.44 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant