Junglewise Threat Intelligence

CVE-2026-53728: Medplum is a developer platform that enables development of healthcare apps. Prior to version 5.1.6, the external identity provider callback

CVE-2026-53728 · Severity: high · CVSS 7.1 · Published 2026-09-03

Vendors: npm.

Executive brief

Medplum is a healthcare data platform that enables external authentication via identity providers. A flaw in the external login callback allows attackers to redirect authorization codes to attacker-controlled endpoints by manipulating redirect URIs to prefix-match (rather than exactly match) registered client URIs. An attacker can intercept these codes and gain full account access to any user logging in via external identity providers.

Technical details

The vulnerability exists in the GET /auth/external callback handler, which validates redirect URIs using a prefix-match check (startsWith) instead of exact equality. The externalCallbackHandler() function passes the attacker-supplied redirectUri to getClientRedirectUri() with a flag enabling partial matching, allowing any URI that starts with a registered redirect URI to be accepted. An attacker who controls the external auth state JSON can inject a malicious redirectUri (e.g., http://callback.audit.local.oastify.com/cb when http://callback.audit.local is registered) to leak the authorization code. Since the attacker also controls the PKCE code_challenge in state, they can redeem the leaked code for a valid session token, achieving account takeover. No authentication is required; the attack exploits the unauthenticated callback endpoint. Patch: upgrade to version 5.1.6 or later.

Affected products

  • Medplum @medplum/core <= 5.1.5

Timeline

  • 2026-07-24: disclosed
  • 2026-07-24: patched: Version 5.1.6 released
  • 2026-08-17: advisory

References