Loading market data...
← Back to CVE feed

CVE-2026-91201

MEDIUM CVSS 5.4 View on NVD ↗

Description

DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Attackers can obtain session tokens and provider account emails by acting as window.opener during OAuth authorization, then use tokens to disconnect victims' cloud storage connectors.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
Published: Sep 14, 2026 23:19 UTC Modified: Sep 14, 2026 23:19 UTC