HomeSecurityLaravel Socialite: Critical Identity Bypass via Facebook OIDC

Laravel Socialite: Critical Identity Bypass via Facebook OIDC

How easily can a Facebook login be bypassed when a valid token is reused? Laravel Socialite contained a critical flaw in nonce checking for Facebook OIDC tokens, allowing unauthenticated attackers to attempt to access user accounts.

Laravel Socialite Facebook OIDC vulnerability

The vulnerability is listed as CVE-2026-73683 and affects Laravel's Socialite package, a library used to connect applications to services like Facebook, GitHub, and Google. According to NVD, versions prior to 5.29.0 are affected.

See also: BdThemes plugins: Supply chain attack creates hidden administrators

What's changing in Laravel Socialite security

The issue is located in Laravel Socialite, specifically in the getUserByOIDCToken() in FacebookProvider.php. The function decodes an OIDC id_token and checks the signature, the audience for which the token was issued, and its issuer. However, until the code change, it did not associate the token's nonce with the nonce of the specific session.

The nonce is a unique value that must correspond to the login process initiated by the user. Without this comparison, an attacker who obtained a valid and unexpired OIDC token issued for the same Facebook application ID could resubmit it to the backend via the userFromToken(). The scenario does not require an attacker account, but does require obtaining a suitable token.

The CVE Alert entry describes the result as an authentication bypass and unauthorized access to victim accounts. The CVSS 3.1 rating is 8.1, with a high impact on confidentiality and integrity. NVD classifies the issue as CWE-294, which is an authentication bypass via replay of a recorded token.

A high score does not mean that every installation is automatically vulnerable. The attack requires access to a token issued for the same App ID, and the NVD rating indicates a high attack complexity. However, reusing a token can have serious consequences when the app uses Facebook as a gateway to sensitive services.

The fix is ​​particularly important for applications that accept OIDC tokens from mobile applications or from interfaces without traditional cookie-based sessions. In such environments, developers should not assume that the absence of a session eliminates the need for nonce matching. The value should be generated, securely stored, and checked before the user session is created.

Check nonce in Facebook token

The Facebook OIDC fix

The Laravel team has merged change request #789 and commit caf714f. The change adds an expected nonce value to the Facebook provider and discards the token when the value is missing or does not match what the application expected.

In the corrected code, Socialite requires a nonce in the OIDC token and uses a safe comparison with the expected value. It also maintains the checks for aud and iss. The current implementation of FacebookProvider now explicitly shows this check.

Application administrators using Facebook Limited Login should check their Composer dependencies and upgrade to a version that includes the fix. The official Laravel documentation explains that Facebook Limited Login returns an OIDC token and that this can be passed to the userFromToken(), so this flow needs special attention.

Account protection from nonce replay

See also: Hotel Wi-Fi DNS poisoning: How hackers steal Microsoft 365 accounts

What development teams should check

Upgrading the package is the first step, but it also requires checking the login flow. Teams should verify that the nonce is generated per session, passed on to Facebook's return, and is not bypassed when the application is running without cookie-based sessions. Using the stateless() requires separate evaluation because it disables session state verification.

It is also a good idea to check the logs for unusual token repetitions, failed nonce attempts, and connections that do not correspond to a recent process start. There is no indication in the CVE record that the vulnerability is being actively exploited, so the immediate upgrade acts as a preventative measure and limits the window of exposure.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Laravel Socialite upgrade for protection

See also: CVE-2026-8508: Zyxel WAX650S exposes captive portal to bypass

The key takeaway for any application using Facebook OIDC is clear: a valid token alone is not enough for secure login. Nonce matching, the updated Laravel Socialite version, and userFromToken() flow control should be treated as a single protection measure.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS