[Security] High: Private options can disable OAuth state validation and enable login CSRF / session swapping
Maintainers usually reply within 4 days
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 38/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Quiet
- Tech stack
- javascript
- Domain
- authentication, security
Research direction
Start with src/core/web_api/p2_api.js at lines 24 and 174-180, then inspect auth0-js/src/web-auth/index.js:345-348 and reproduce the missing-state callback flow described in the issue. Add regression coverage for unsolicited callback fragments and missing-state handling, and verify that attacker-controlled callbacks are rejected unless explicitly trusted.
Written by the indexing model from the issue text.
Description
Severity: High
CWE: CWE-352 (Cross-Site Request Forgery), CWE-384 (Session Fixation)
Affected file/line:
src/core/web_api/p2_api.js:24src/core/web_api/p2_api.js:174-180- Supporting behavior in bundled dependency:
auth0-js/src/web-auth/index.js:345-348
Root cause:
Lock copies the private _enableIdPInitiatedLogin / _enableImpersonation options into this._enableIdPInitiatedLogin and always forwards that flag to client.parseHash() as __enableIdPInitiatedLogin. In the bundled auth0-js flow, validateAuthenticationResponse() skips the normal state mismatch rejection when both the callback fragment and stored transaction are missing state and __enableIdPInitiatedLogin is true. That means a callback route can accept an unsolicited login result without a matching local transaction.
Reproduction steps:
- Initialize Lock with
_enableIdPInitiatedLogin: trueor_enableImpersonation: true. - Start an authentication flow for the same Auth0 application as an attacker and capture the resulting callback fragment.
- Ensure the victim browser has no matching local transaction state stored for that callback route.
- Navigate the victim to a callback URL containing the attacker-controlled fragment, for example:
https://app.example/callback#id_token=ATTACKER_ID_TOKEN&access_token=ATTACKER_ACCESS_TOKEN&token_type=Bearer parseHash()accepts the attacker identity because state validation is bypassed under the no-state/no-transaction condition.
Suggested fix:
- Do not forward
__enableIdPInitiatedLoginfrom Lock by default. - Fail closed on callback parsing when
stateis missing unless the flow is explicitly authenticated as a trusted IdP-initiated callback. - Remove or tightly gate
_enableImpersonation/_enableIdPInitiatedLoginin public Lock integrations. - Add regression tests for unsolicited callback fragments and missing-state callback handling.
Commit tested: 75336c98dbdc8ee01f4c2651e50d4c65cda32f01
- Dominant language
- JavaScript
- Stars
- 1.1k
- Forks
- 563
- Avg merge
- 4d 11h
- Merged PRs (30d)
- 10
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from auth0/lock
-
Signup crashes with "policy.toJS is not a function" when password policy is unavailable (15.0.1)Possibly taken @thduttonuk claimed this 8 days ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 90/100
Maintainers usually reply within 4 days
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
Maintainers usually reply within 1 day
-
documentation good first issue help wanted
Difficulty 1/5 1-3 hours Newbie friendliness 85/100
zmo2s/agent-toolbox#23 ·
-
[Bug]: [MCP/CLI] Bare loopback IP addresses (127.0.0.1:port) and hosts with ports fail to navigate due to erroneous scheme inferencePossibly taken @alok-108 claimed this today. Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
microsoft/playwright#43263 ·
Maintainers usually reply within 1 day