Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none in github.com/pocket-id/pocket-id/backend
02 Sep
Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method in github.com/pocket-id/pocket-id/backend
18 Aug
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions in github.com/pocket-id/pocket-id/backend
18 Aug