DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Attackers can obtain session tokens and provider account emails by acting as window.opener during OAuth authorization, then use tokens to disconnect victims' cloud storage connectors.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-14 23:19
Updated : 2026-09-14 23:19
NVD link : CVE-2026-91201
Mitre link : CVE-2026-91201
CVE.ORG link : CVE-2026-91201
JSON object : View
Products Affected
No product.
CWE
CWE-346
Origin Validation Error
