CVE-2026-79786
7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Summary
Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without validation, allowing attackers to register clients pointing to attacker-controlled hosts. Attackers can send authorization URLs to signed-in users, capture their authorization codes upon consent approval, and exchange them for access tokens to hijack MCP sessions.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| coroot | coroot | 1.20.2 <= 1.24.5 | affected |
Weaknesses
- CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
References
- https://github.com/coroot/coroot
- https://github.com/coroot/coroot/issues/929
- https://github.com/coroot/coroot/blob/v1.24.5/api/mcp_oauth.go
- https://www.vulncheck.com/advisories/coroot-1.20.2-through-1.24.5-unvalidated-redirect-uri-in-mcp-oauth-client-registration
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.