
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14546 is a Cross-Site Request Forgery (CSRF) vulnerability in the fastapi-sso Python package affecting all versions before 0.19.0. The flaw stems from improper validation of the OAuth state parameter during the authentication callback, enabling a remote attacker to trick a victim into visiting a malicious callback URL and linking the attacker's account to the victim's internal account — a "1-click account takeover" scenario. The vulnerability was discovered by David Borș of Snyk Security Research, disclosed on December 9, 2025, and published on December 19, 2025. It carries a CVSS v3.1 base score of 6.3 (Medium) and a CVSS v4.0 score of 5.4 (Medium) per NVD (Github Advisory, Snyk).
The root cause is classified as CWE-285 (Improper Authorization) and CWE-352 (Cross-Site Request Forgery). The get_login_url method in fastapi_sso/sso/base.py generates an OAuth state value but never persists it server-side or binds it to the user's session. During the callback, verify_and_process blindly copies the attacker-supplied state query parameter into self._state without comparing it against any trusted stored value, violating RFC 6749 Section 10.12. The fix (commit 6117d1a) addresses this by storing the state in a sso_state cookie during login redirect and validating it against the callback's state parameter before processing (GitHub Commit, GitHub Issue, Snyk).
Successful exploitation allows an attacker to permanently link their own SSO identity to a victim's existing application account, effectively achieving account takeover. The primary impact is high confidentiality loss — the attacker gains access to the victim's account and all associated data — with a low integrity impact from the unauthorized account association. Availability is not affected. The scope of impact depends on the application's account-linking logic, but in the worst case, the attacker gains full persistent access to the victim's account without the victim's knowledge (Snyk, GitHub Issue).
Snyk has documented a proof-of-concept (PoC) for this vulnerability, and the CVSS v4.0 exploit maturity is rated "Proof of Concept." There is no evidence of active in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.1% (27th percentile), indicating a low but non-negligible probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Snyk, Github Advisory).
code and state from the OAuth provider — but stops before submitting the callback to the application./auth/callback?code=ATTACKER_CODE&state=ATTACKER_STATE) using their own code and state values.verify_and_process accepts the attacker-supplied state without checking it against a session-bound value, the callback is processed successfully. The attacker's grant code is exchanged with the OAuth provider./auth/callback) from IP addresses or user agents inconsistent with the victim's normal session; callback requests where the state parameter does not match any recently initiated login flow.Upgrade fastapi-sso to version 0.19.0 or later, which enforces state validation by storing the state in a sso_state cookie during the login redirect and verifying it against the callback's state parameter before processing. There is no documented configuration-based workaround for older versions; upgrading is the only reliable fix. As an additional defense-in-depth measure, application developers should implement their own session-bound state validation and avoid using non-random, predictable state values as previously suggested in the library's documentation (Github Advisory, GitHub Commit).
The vulnerability was reported by David Borș of Snyk Security Research and disclosed responsibly to the maintainer on December 9, 2025, with a fix released on December 19, 2025. The GitHub issue was labeled as a security concern by the repository maintainer. Snyk published a detailed advisory and PoC description, and the issue received coverage from several vulnerability tracking platforms. No significant broader media coverage or notable community controversy has been identified (Snyk, GitHub Issue).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."