Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x85x-q6hq-hm4x

Опубликовано: 15 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 5.4

Описание

DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Attackers can obtain session tokens and provider account emails by acting as window.opener during OAuth authorization, then use tokens to disconnect victims' cloud storage connectors.

DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Attackers can obtain session tokens and provider account emails by acting as window.opener during OAuth authorization, then use tokens to disconnect victims' cloud storage connectors.

EPSS

Процентиль: 4%
0.0014
Низкий

5.3 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-346

Связанные уязвимости

CVSS3: 5.4
nvd
5 дней назад

DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Attackers can obtain session tokens and provider account emails by acting as window.opener during OAuth authorization, then use tokens to disconnect victims' cloud storage connectors.

EPSS

Процентиль: 4%
0.0014
Низкий

5.3 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-346