Executive brief
Authlib, a library used to implement login and authorization services, contains a flaw that allows attackers to redirect users to malicious websites. By sending a specially crafted login request that omits a required security setting, an attacker can trick the server into sending a user to a phishing page. This can be used to steal user credentials by making the malicious site appear as if it is part of a trusted login process.
Technical details
An open redirect exists in Authlib's `OpenIDImplicitGrant` and `OpenIDHybridGrant` implementations. The vulnerability occurs because the `validate_authorization_request` method checks for the presence of the 'openid' scope before validating the `redirect_uri` against the registered client configuration. If the scope is missing, the library raises an `InvalidScopeError` that includes the unvalidated `redirect_uri` from the request payload. When this error is processed, the server issues an HTTP 302 redirect to the attacker-supplied URL. This bypasses standard OAuth 2.0 security requirements that mandate URI validation before redirection. The issue is fixed in versions 1.6.12 and 1.7.1.
Affected products
- Authlib Authlib <= 1.6.11, 1.7.0
Timeline
- 2026-05-07: advisory: GitHub Advisory published
- 2026-05-13: disclosed