top of page
perceptive_background_267k.jpg

Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without validation, allowing attackers to r…

Published:

25 augustus 2026 om 00:00:00

Alert date:

25 augustus 2026 om 22:05:19

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

CVE-2026-79786 affects Coroot versions 1.20.2 through 1.24.5, where the MCP OAuth dynamic client registration endpoint fails to validate redirect URIs. The endpoint is unauthenticated, allowing any attacker to register OAuth clients with redirect URIs pointing to attacker-controlled hosts. Attackers can craft and distribute malicious authorization URLs targeting signed-in users. When a victim approves consent, their authorization code is captured by the attacker. The attacker can then exchange the stolen authorization code for valid access tokens. This results in full MCP session hijacking. The vulnerability is a classic OAuth open redirect leading to authorization code interception. A fix is referenced in the Coroot GitHub repository at version 1.24.5's mcp_oauth.go file. Users of affected versions should upgrade immediately or restrict access to the registration endpoint.

Technical details

Mitigation steps:

Affected products:

Coroot 1.20.2
Coroot 1.24.5

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page