VDB
Sign up
CRITICAL9.6

GHSA-wr5g-q49g-548w

Expo SDK has an OAuth vulnerability

Quick fix

GHSA-wr5g-q49g-548w — expo: upgrade to the fixed version with the command below.

npm install expo@48.0.0

Details

A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the "Expo AuthSession Redirect Proxy" for social sign-in. This can be achieved once a victim clicks a malicious link. The link itself may be sent to the victim in various ways (including email, text message, an attacker-controlled website, etc).

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/expo
Introduced in: 0Fixed in: 48.0.0
Fixnpm install expo@48.0.0

References