NextAuth.js
cpe:2.3:a:nextauth.js:next-auth:*:*:*:*:node.js:*:*
- < 3.29.3
- < 4.3.3
A open redirect vulnerability has been identified in NextAuth.js versions prior to 3.29.3 and 4.3.3. This issue arises when developers implement an OAuth 1 provider, such as Twitter, which is the only built-in provider using OAuth 1. The vulnerability allows for URL redirection to untrusted sites.
Exploitation of this vulnerability could lead to open redirect, allowing attackers to redirect users to malicious sites.
Users can upgrade to NextAuth.js version 3.29.3 or 4.3.3, both of which contain the patch for this vulnerability. For those unable to upgrade, a workaround involves adding specific configuration to the 'callbacks' option to manage redirect URLs.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.