Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-91201

Опубликовано: 14 сент. 2026
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Attackers can obtain session tokens and provider account emails by acting as window.opener during OAuth authorization, then use tokens to disconnect victims' cloud storage connectors.

EPSS

Процентиль: 4%
0.0014
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-346

Связанные уязвимости

CVSS3: 5.4
github
4 дня назад

DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Attackers can obtain session tokens and provider account emails by acting as window.opener during OAuth authorization, then use tokens to disconnect victims' cloud storage connectors.

EPSS

Процентиль: 4%
0.0014
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-346