Security: flownative/flow-openidconnect-client
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Refresh token is stored in the session without renewing the session identifierGHSA-hhq2-h4jg-rv77 published
Sep 14, 2026 by robertlemkeModerate -
JWT cookie is readable by scripts and is also set for bearer tokensGHSA-h2cv-4hrc-85q7 published
Sep 14, 2026 by robertlemkeModerate -
Authorization code flow is not bound to the browser which started itGHSA-8cv6-3mf6-q28j published
Sep 14, 2026 by robertlemkeModerate -
Roles of existing accounts can be obtained with an unverified email addressGHSA-rff6-g392-vgjg published
Sep 14, 2026 by robertlemkeHigh -
Identity tokens are accepted without issuer and audience validationGHSA-7xcp-7727-7fjh published
Sep 14, 2026 by robertlemkeHigh
Learn more about advisories related to flownative/flow-openidconnect-client in the GitHub Advisory Database