CVE-2026-79786

Source
https://cve.org/CVERecord?id=CVE-2026-79786
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-79786.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-79786
Published
2026-08-25T18:23:14.494Z
Modified
2026-08-27T11:47:51.209832121Z
Severity
  • 7.0 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Coroot 1.20.2 through 1.24.5 Unvalidated Redirect URI in MCP OAuth Client Registration
Details

Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without validation, allowing attackers to register clients pointing to attacker-controlled hosts. Attackers can send authorization URLs to signed-in users, capture their authorization codes upon consent approval, and exchange them for access tokens to hijack MCP sessions.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-601"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/79xxx/CVE-2026-79786.json"
}
References

Affected packages

Git / github.com/coroot/coroot

Affected ranges

Type
GIT
Repo
https://github.com/coroot/coroot
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.20.2"
        },
        {
            "last_affected": "1.24.5"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v1.*
v1.20.1
v1.20.2
v1.21.0
v1.21.1
v1.22.0
v1.22.1
v1.22.2
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.24.1
v1.24.2
v1.24.3
v1.24.4
v1.24.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-79786.json"