Authlib has 1-click Account Takeover vulnerability
I am writing to you from the Security Labs team at Snyk to report a security issue affecting Authlib, which we identified during a recent research project. We have identified a vulnerability that can result in a 1-click Account Takeover in applications that use the Authlib library. (5.7 CVSS v3: AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N) Description Cache-backed state/request-token storage is not tied to the initiating user session, so CSRF is possible for any attacker …