A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the AI Playground's OAuth callback handler. The error_description query parameter was directly interpolated into an HTML script tag without proper escaping, allowing attackers to execute arbitrary JavaScript in the context of the victim's session.
The OAuth callback handler in site/ai-playground/src/server.ts directly interpolated the authError value, sourced from the error_description query parameter, into an inline <script> tag.
An attacker could craft a malicious link that, when clicked by a victim, would:
agents@0.3.10configureOAuthCallback with custom error handling in their own applications should ensure all user-controlled input is escaped before interpolation.Disclosed responsibly by Nishant Kumawat
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2026-02-13T21:04:00Z",
"nvd_published_at": null,
"severity": "MODERATE"
}