Executive brief
OpenClaude is an open-source terminal application that integrates with various AI services including xAI for authentication. A vulnerability in the xAI OAuth callback handler allows an attacker to disrupt user login flows by sending a malicious request from an external website, causing the legitimate authentication to fail without the user's knowledge. This can prevent users from logging into the application when attempting to use xAI-based features.
Technical details
The vulnerability is a state validation bypass in the xAI OAuth loopback callback handler (src/services/api/xaiOAuthCallback.ts). The function waitForCallback() processes the error query parameter before validating the CSRF state token, allowing an unauthenticated attacker to issue a cross-origin GET request to http://127.0.0.1:56121/callback?error=access_denied and prematurely terminate a legitimate OAuth flow. An attacker can trigger this via an image tag or fetch request on a malicious website visited during the victim's authentication attempt. The server runs on a fixed port (56121), making it consistently reachable. When the error parameter is detected, the handler marks the flow as settled and rejects the promise without verifying the state parameter, causing subsequent legitimate OAuth responses to be ignored. A patch should reorder validation to check the state token before processing error or code parameters, consistent with fixes applied to related MCP OAuth handlers.
Affected products
- Gitlawb openclaude up to 0.30.0
Timeline
- 2026-08-07: disclosed: Issue #2101 opened on GitHub
- 2026-09-14: advisory: CVE-2026-90712 published