NextAuth.js Open Redirect Vulnerability in OAuth 1 Provider Implementation

Vulnerability

A open redirect vulnerability has been identified in NextAuth.js versions prior to 3.29.3 and 4.3.3. This issue arises when developers implement an OAuth 1 provider, such as Twitter, which is the only built-in provider using OAuth 1. The vulnerability allows for URL redirection to untrusted sites.

Impact

Exploitation of this vulnerability could lead to open redirect, allowing attackers to redirect users to malicious sites.

Remediation

Users can upgrade to NextAuth.js version 3.29.3 or 4.3.3, both of which contain the patch for this vulnerability. For those unable to upgrade, a workaround involves adding specific configuration to the 'callbacks' option to manage redirect URLs.

Added: Jun 22, 2026, 10:58 AM
Updated: Jun 22, 2026, 10:58 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
0.2
exploitability
6.4
remediation
8.3
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.