liamcurry / passport-steam

Steam (OpenID) authentication strategy for Passport and Node.js.
MIT License
349 stars 104 forks source link

Potential vulnerability #119

Closed axotion closed 1 year ago

axotion commented 1 year ago

A new exploit has just dropped in causing massive problems of hijacking users/admins' accounts

https://twitter.com/variancewarren/status/1670405889113702400

Do we know if this package is vulnerable to this?