GHSA-h29v-hj44-q8cv
CRITICALCVE-2026-54072The /authorize endpoint accepts any redirecturi without validating it against AllowedOrigins. When responsetype=token or responsetype=idtoken, the server appends accesstoken, idtoken, and refreshtoken as query parameters and issues a 302 redirect to the attacker-supplied URL. An unauthenticated attacker can obtain the required clientid from the public /graphql?query={meta{clientid}} endpoint.
- Affected
- < 0.0.0-20260409051328-bd3f5baf6d3d, >=0, <0.0.0-20260409051328-bd3f5baf6d3d
- Fixed in
- 0.0.0-20260409051328-bd3f5baf6d3d
- Weakness
- CWE-601
- Published
- 2026-07-10
- Source
- github