Pocket ID: Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none
Published Aug 28, 2026
4.3
MEDIUMCVSS 3.1
EPSS 0.37%
Description
Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to services. From 2.6.0 until 2.9.0, frontend/src/routes/authorize/+page.ts reads the redirect_uri query parameter and frontend/src/routes/authorize/+page.svelte uses the raw callbackURL in redirectWithError when prompt=none cannot complete silent authorization. The client-side path only blocks javascript and data schemes and does not invoke the backend callback allow-list validation, so an unauthenticated attacker who knows a valid client_id can redirect a victim browser to an arbitrary HTTP or HTTPS origin for phishing or OIDC error and state smuggling. This issue is fixed in version 2.9.0.
Affected products
-
- Version >= 2.6.0, < 2.9.0StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
github.com/pocket-id/pocket-id/backend
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/pocket-id/pocket-id/backend | 0 | not fixed |
Remediation
No remediation recorded yet.
References (4)
- https://github.com/advisories/GHSA-2wvm-8mvp-22qv Advisory
- https://github.com/pocket-id/pocket-id/commit/8a7577497131229badb35cb4b3a4227b1300afff x_refsource_MISC
- https://github.com/pocket-id/pocket-id/releases/tag/v2.9.0 x_refsource_MISC
- https://github.com/pocket-id/pocket-id/security/advisories/GHSA-2wvm-8mvp-22qv exploitx_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-2wvm-8mvp-22qv | Advisory | |
| https://github.com/pocket-id/pocket-id/commit/8a7577497131229badb35cb4b3a4227b1300afff | x_refsource_MISC | |
| https://github.com/pocket-id/pocket-id/releases/tag/v2.9.0 | x_refsource_MISC | |
| https://github.com/pocket-id/pocket-id/security/advisories/GHSA-2wvm-8mvp-22qv | exploitx_refsource_CONFIRM |
Change history (0)
No recorded changes yet.