Executive brief
Doorkeeper OpenID Connect is a Ruby gem that adds OpenID Connect authentication to Rails applications. The Dynamic Client Registration endpoint allows applications to self-register and request OAuth scopes, but prior to version 1.10.4 it failed to validate requested scopes against the server's configured list. An attacker could register a malicious client claiming administrative or other privileged scopes, then obtain tokens with those unintended permissions, effectively elevating their access beyond what the server intended to grant.
Technical details
The vulnerability is an improper authorization / scope validation flaw in the Dynamic Client Registration (DCR) endpoint. In DynamicClientRegistrationController#application_params, user-supplied scope parameters are persisted directly without validation against Doorkeeper.configuration.scopes or optional_scopes. The issue is compounded because enforce_configured_scopes is off by default, and Doorkeeper's ScopeChecker prioritizes application-level scopes over server-level scopes during token issuance. This allows an unauthenticated attacker to self-register a client with arbitrary scopes (e.g., "admin") and later obtain tokens claiming those privileges. The fix in v1.10.4 validates DCR-supplied scopes against the server's configured scope set, silently dropping unrecognized ones and rejecting requests where all scopes are invalid.
Affected products
- doorkeeper-gem Doorkeeper OpenID Connect prior to 1.10.4
Timeline
- 2026-08-05: disclosed
- 2026-07-02: patched: version 1.10.4 released