Executive brief
Feathers is a JavaScript backend framework that includes OAuth authentication support. An unauthenticated attacker can forge a malicious request to bypass the OAuth authentication flow and obtain a valid access token for any existing user account, leading to complete account takeover without needing valid OAuth credentials.
Technical details
The vulnerability exists in the OAuth callback handler (/oauth/:provider/callback) which contains a fallback chain that reaches the raw request query parameters when the OAuth provider's session/state validation is empty. Since an attacker never initiates a legitimate OAuth authorize flow, the Grant library has no session to validate and produces no response, causing the fallback to fire. The attacker can then inject a forged profile via query parameters, which is used for entity lookup and JWT token generation, resulting in a valid access token for an arbitrary user. This is an unauthenticated, network-accessible bypass of the authentication mechanism. The vulnerability affects @feathersjs/authentication-oauth versions 5.0.0 through 5.0.41 and is fixed in version 5.0.42.
Affected products
- Feathers authentication-oauth 5.0.0 through 5.0.41
Timeline
- 2026-03-10: disclosed
- 2026-03-10: patched: Fixed in version 5.0.42