Junglewise Threat Intelligence

CVE-2026-29792: Feathers OAuth callback account takeover

CVE-2026-29792 · Severity: medium · CVSS 4 · Published 2026-03-10

Technologies: Feathers Authentication-Oauth, @feathersjs/authentication-oauth (npm). Vendors: Feathers, npm.

Executive brief

Feathers is a JavaScript backend framework that includes OAuth authentication support. An unauthenticated attacker can forge a malicious request to bypass the OAuth authentication flow and obtain a valid access token for any existing user account, leading to complete account takeover without needing valid OAuth credentials.

Technical details

The vulnerability exists in the OAuth callback handler (/oauth/:provider/callback) which contains a fallback chain that reaches the raw request query parameters when the OAuth provider's session/state validation is empty. Since an attacker never initiates a legitimate OAuth authorize flow, the Grant library has no session to validate and produces no response, causing the fallback to fire. The attacker can then inject a forged profile via query parameters, which is used for entity lookup and JWT token generation, resulting in a valid access token for an arbitrary user. This is an unauthenticated, network-accessible bypass of the authentication mechanism. The vulnerability affects @feathersjs/authentication-oauth versions 5.0.0 through 5.0.41 and is fixed in version 5.0.42.

Affected products

  • Feathers authentication-oauth 5.0.0 through 5.0.41

Timeline

  • 2026-03-10: disclosed
  • 2026-03-10: patched: Fixed in version 5.0.42

References

Related threats