Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without validation, allowing attackers to register clients pointing to attacker-controlled hosts. Attackers can send authorization URLs to signed-in users, capture their authorization codes upon consent approval, and exchange them for access tokens to hijack MCP sessions.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without validation, allowing attackers to register clients pointing to attacker-controlled hosts. Attackers can send authorization URLs to signed-in users, capture their authorization codes upon consent approval, and exchange them for access tokens to hijack MCP sessions. | |
| Title | Coroot 1.20.2 through 1.24.5 Unvalidated Redirect URI in MCP OAuth Client Registration | |
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-25T18:23:14.494Z
Reserved: 2026-08-25T14:32:37.763Z
Link: CVE-2026-79786
No data.
Status : Received
Published: 2026-08-25T19:16:54.750
Modified: 2026-08-25T19:16:54.750
Link: CVE-2026-79786
No data.
OpenCVE Enrichment
No data.