# Replit — June 6, 2023, Single-Sign-On Security Vulnerability

- Company: Replit (replit.com)
- Announced: 2023-06-12T12:00:00+00:00
- Category: safety-policy-update
- Coverage: not counted
- Announcement: yes
- Group: announcements
- Source: https://replit.com/blog/june-6-sso-security-vulnerability
- Record: https://forck.live/items/18094-june-6-2023-single-sign-on-security-vulnerability
- Subject: Replit Agent

Replit identified and patched a single-sign-on security vulnerability on June 6, 2023, after auditing its authentication systems. The vulnerability could have allowed an attacker to impersonate affected users via a fraudulent GitHub account under certain conditions, though Replit found no evidence of exploitation. As a precaution, Replit logged out all users who had ever used SSO with GitHub, Facebook, or Apple accounts.

## Evidence

Verbatim from https://replit.com/blog/june-6-sso-security-vulnerability:

> On Tuesday, June 6, while auditing our authentication systems, we investigated a possible vulnerability related to our single-sign-on functionality. We patched the vulnerability the same day and proceeded to investigate whether any users could’ve been affected by it.

---

Record: https://forck.live/items/18094-june-6-2023-single-sign-on-security-vulnerability
Catalogue: https://forck.live/llms.txt
Current issue: https://forck.live/feed.md
