Analysis of OAuth 2.0 Vulnerabilities Arising from Weak Implementation Choices
L. Jiljana Petrovic · International Journal of Innovative Solutions in Engineering · 2025
This project showcases authentication and authorization frameworks, such as OAuth 2.0 and OpenID Connect, by implementing a simplified OAuth 2.0 system. To illustrate possible attacks on such a system, a demonstration project is implemented using an incorrectly configured OAuth 2.0 authentication flow and an insecure OAuth client. Solutions are presented that both prevent potential attacks and protect user data, even in the event of a successful attack. The demonstration shows that a maliciously injected script can read a user’s access token and send it to the attacker, who can use it to access the user’s private data, effectively hijacking the session. This setup demonstrates that, while OAuth 2.0 provides a secure protocol, security is undermined by weak implementation choices. In particular, storing tokens in localStorage and allowing XSS in the client can completely defeat OAuth’s protections. The findings emphasize that protocol security does not guarantee overall system security without secure practices. Authentication, OAuth 2.0, Access Token Theft, Cross-Site Scripting, React, LocalStorage.