Executive brief
Plack::Middleware::OAuth is a Perl library used by web applications to handle user logins via OAuth 2.0 providers like Google or GitHub. A security flaw in versions up to 0.10 fails to verify the 'state' parameter during the login process, which allows an attacker to trick a victim into linking the attacker's account to the victim's session. This can lead to account takeover, where the attacker maintains permanent access to the victim's account using their own social media or email credentials.
Technical details
Plack::Middleware::OAuth through version 0.10 fails to implement the OAuth 2.0 'state' parameter, a critical security measure against Cross-Site Request Forgery (CSRF). Specifically, the RequestTokenV2 component generates authorization redirects without a state value, and AccessTokenV2 registers the resulting token into the session without verifying that the callback originated from a request initiated by that same session. An attacker can exploit this by initiating an OAuth flow with their own credentials and forcing a victim's browser to complete the callback. This results in the attacker's identity being associated with the victim's application session, potentially allowing persistent account access if the application links these identities. A patch has been proposed in GitHub pull request #13.
Affected products
- CORNELIUS Plack::Middleware::OAuth 0 through 0.10
Timeline
- 2026-07-03: patched: Pull request #13 submitted to add state support
- 2026-07-04: disclosed: CVE-2026-12740 published