GHSA-c9w5-qp6m-m395

Suggest an improvement
Source
https://github.com/advisories/GHSA-c9w5-qp6m-m395
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-c9w5-qp6m-m395/GHSA-c9w5-qp6m-m395.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-c9w5-qp6m-m395
Aliases
Published
2026-05-28T18:30:32Z
Modified
2026-07-21T19:19:17Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check
Details

Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExchangeToken function in object/token_oauth.go validates JWT signatures but does not verify that the token's user belongs to the same organization as the target application. This can result in privilege escalation across organizational boundaries.

Database specific
{
    "cwe_ids":  [
        "CWE-269",
        "CWE-863"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-09T23:32:36Z",
    "nvd_published_at":  "2026-05-28T17:16:34Z",
    "severity":  "CRITICAL"
}
References

Affected packages

Go / github.com/casdoor/casdoor

Package

Name
github.com/casdoor/casdoor
View open source insights on deps.dev
Purl
pkg:golang/github.com/casdoor/casdoor

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.387.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-c9w5-qp6m-m395/GHSA-c9w5-qp6m-m395.json"