


Perceptive Security
SOC/SIEM Consultancy

Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without validation, allowing attackers to r…
Published:
25 augustus 2026 om 00:00:00
Alert date:
25 augustus 2026 om 22:05:19
Source:
nvd.nist.gov
Web Technologies, Identity & Access
CVE-2026-79786 affects Coroot versions 1.20.2 through 1.24.5, where the MCP OAuth dynamic client registration endpoint fails to validate redirect URIs. The endpoint is unauthenticated, allowing any attacker to register OAuth clients with redirect URIs pointing to attacker-controlled hosts. Attackers can craft and distribute malicious authorization URLs targeting signed-in users. When a victim approves consent, their authorization code is captured by the attacker. The attacker can then exchange the stolen authorization code for valid access tokens. This results in full MCP session hijacking. The vulnerability is a classic OAuth open redirect leading to authorization code interception. A fix is referenced in the Coroot GitHub repository at version 1.24.5's mcp_oauth.go file. Users of affected versions should upgrade immediately or restrict access to the registration endpoint.
Technical details
Mitigation steps:
Affected products:
Coroot 1.20.2
Coroot 1.24.5
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-79786
https://github.com/coroot/coroot
https://github.com/coroot/coroot/blob/v1.24.5/api/mcp_oauth.go
https://github.com/coroot/coroot/issues/929
https://www.vulncheck.com/advisories/coroot-1.20.2-through-1.24.5-unvalidated-redirect-uri-in-mcp-oauth-client-registration
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
