CVE-2026-79786: Coroot 1.20.2 through 1.24.5 Unvalidated Redirect URI in MCP OAuth Client Registration

Published Aug 25, 2026
·
Updated

Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without validation, allowing attackers to register clients pointing to attacker-controlled hosts. Attackers can send authorization URLs to signed-in users, capture their authorization codes upon consent approval, and exchange them for access tokens to hijack MCP sessions.

Affected Software

1 affected component
Coroot Coroot>=1.20.2<=1.24.5

Event History

Aug 25, 2026
CVE Published
via MITRE·06:23 PM
Data Sourced
via MITRE·06:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Coroot versions 1.20.2 through 1.24.5 are affected where the MCP OAuth dynamic client registration endpoint is available. The endpoint is unauthenticated, so exploitation does not require an existing Coroot account.

2

What does an attacker need to exploit this issue?

An attacker can register an OAuth client with a syntactically valid redirect URI pointing to an attacker-controlled host, then induce a signed-in user to visit an authorization URL and approve consent. Successful exploitation requires user interaction and consent approval.

3

What can an attacker obtain after successful exploitation?

The attacker can receive the authorization code at the attacker-controlled redirect URI and exchange it for an access token. This can enable hijacking of the affected user's MCP session.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203