Executive brief
A flaw in the oauth-server component allows attackers to craft malicious URLs that redirect authenticated users to attacker-controlled websites after they approve or deny OAuth access requests. This vulnerability can be exploited to conduct phishing attacks, tricking users into revealing sensitive credentials or personal information on fake websites that impersonate legitimate services.
Technical details
This is an open redirect vulnerability (CWE-601) in the OAuth server's grant approval handler where the 'then' parameter is not properly validated. A remote attacker with network access can craft a malicious URL that, when clicked by an authenticated user and after they approve or deny the OAuth grant, redirects them to an attacker-controlled origin. The vulnerability requires user interaction (the user must approve or deny the grant) but does not require authentication to craft the malicious URL. Importantly, OAuth tokens, authorization codes, and session credentials are not exposed through the redirect—the authorization code is issued separately to the client's registered redirect_uri. No mitigation is available; patching is required to resolve the issue.
Affected products
- oauth-server
Timeline
- 2026-08-11: disclosed