Skip to content

Fix OAuth state check bypass (security)

Choose a tag to compare

@github-actions github-actions released this 27 Sep 12:51
· 35 commits to 6.x since this release
Immutable release. Only release title and notes can be modified.

5.1.2 (2026-09-27)

This release fixes a security vulnerability. All users of @adonisjs/ally v5 should upgrade.

The OAuth2 and OAuth1 drivers accepted a callback with no state param (or no oauth_token param for OAuth1) when the state cookie was also missing. An attacker could use this to sign a victim in to the attacker's account, or to link the attacker's provider account to the victim's account. A missing state cookie now counts as a state mismatch, so stateMisMatch() returns true and accessToken() and user() throw E_OAUTH_STATE_MISMATCH.

See the security advisory for details: GHSA-j577-w94j-8p3p

  • fix: treat a missing state cookie as a state mismatch (4684e3d)

Full Changelog: v5.1.1...v5.1.2