Skip to content

DOM Redirect on Microsoft OAuth Flow

Moderate
damencho published GHSA-5fx7-wgcr-fj78 Nov 13, 2025

Package

No package listed

Affected versions

< 2.0.10532

Patched versions

None

Description

Impact

Allows attackers to hijack the OAuth authentication window for Microsoft accounts.

Patches

Fixed in version 2.0.10532.

Workarounds

No, upgrading is necessary.

Reported by

Gustavo Saez Ferreira and Lucas de Souza Silva.

Severity

Moderate

CVE ID

CVE-2025-64754

Weaknesses

No CWEs

Credits