GHSA-m44r-7c5h-m6mj
HIGHCVE-2026-53728The external identity provider callback at GET /auth/external accepts attacker-controlled redirect URIs that only need to start with a registered client redirect URI, rather than matching exactly. After a successful external IdP login, the server appends Medplum login and code values to that attacker-supplied URL and issues a redirect.
- Affected
- >=0, <5.1.6, <= 5.1.5
- Fixed in
- 5.1.6
- Weakness
- CWE-345
- Published
- 2026-08-17
- Source
- osv