Critical severity9.6NVD Advisory· Published Apr 24, 2023· Updated Jun 17, 2026
CVE-2023-28131
CVE-2023-28131
Description
A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the "Expo AuthSession Redirect Proxy" for social sign-in. This can be achieved once a victim clicks a malicious link. The link itself may be sent to the victim in various ways (including email, text message, an attacker-controlled website, etc).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
exponpm | < 48.0.0 | 48.0.0 |
Affected products
3- Range: All versions prior to SDK 48.* (Affected SDK 45.*, 46.* and 47.*)
- cpe:2.3:a:expo:expo_software_development_kit:*:*:*:*:*:*:*:*Range: >=45.0.0,<48.0.0
Patches
Vulnerability mechanics
References
4- blog.expo.dev/security-advisory-for-developers-using-authsessions-useproxy-options-and-auth-expo-io-e470fe9346dfnvdMitigationThird Party AdvisoryWEB
- github.com/advisories/GHSA-wr5g-q49g-548wghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-28131ghsaADVISORY
- www.darkreading.com/endpoint/oauth-flaw-in-expo-platform-affects-hundreds-of-third-party-sites-appsnvdWEB
News mentions
0No linked articles in our index yet.