CVE-2026-42565
MEDIUM@workos/authkit-session: Open Redirect via state-derived redirect target
Title source: cnaDescription
@workos/authkit-session is a toolkit for building WorkOS AuthKit framework integrations. Prior to 0.5.1, an open redirect vulnerability exists in AuthService.handleCallback due to insufficient validation of the returnPathname value derived from the OAuth state parameter. The state parameter is round-tripped through the identity provider (IdP) and can be influenced by an attacker. The handleCallback function decodes and returns returnPathname without enforcing restrictions on origin or scheme. As a result, attacker-controlled values may be returned to the application. If this value is used directly in a redirect, it may cause the user to be redirected to an external, attacker-controlled site. This vulnerability is fixed in 0.5.1.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/workos/authkit-session/security/advisories/GHSA-vvvv-983w-r7pv
X_Refsource_Misc x_refsource_misc
https://github.com/workos/authkit-session/commit/f56e1d6214a93160759e5677b7a3d772b244db39
X_Refsource_Misc x_refsource_misc
https://github.com/workos/authkit-session/releases/tag/v0.5.1
Scores
CVSS v3
4.3
EPSS
0.0020
EPSS Percentile
9.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-601
Status
published
Products (2)
workos/authkit-session
0 - 0.5.1npm
workos/authkit-session
< 0.5.1
Published
May 11, 2026
Tracked Since
May 12, 2026