Back

HIGH

Coroot 1.20.2 through 1.24.5 Unvalidated Redirect URI in MCP OAuth Client Registration

Published Aug 25, 2026

Description

Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without validation, allowing attackers to register clients pointing to attacker-controlled hosts. Attackers can send authorization URLs to signed-in users, capture their authorization codes upon consent approval, and exchange them for access tokens to hijack MCP sessions.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 25, 2026
Updated Aug 28, 2026
Reserved Aug 25, 2026
CISA Vulnrichment
Updated Aug 28, 2026
NVD
Status Received
Modified Aug 28, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulnCheck
Published Aug 25, 2026
Updated Aug 28, 2026
Exploited since n/a
EUVD-2026-65698