CVE-2026-91201: DocsGPT through 0.20.0 OAuth Token Disclosure via Wildcard postMessage
DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Attackers can obtain session tokens and provider account emails by acting as window.opener during OAuth authorization, then use tokens to disconnect victims' cloud storage connectors.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
DocsGPT deployments running version 0.20.0 or earlier are affected when users authorize OAuth-based cloud storage connectors. The attack targets a victim during the OAuth authorization flow.
What does an attacker need to exploit it?
An attacker needs to act as the window.opener during OAuth authorization. No authentication or other privileges are indicated, but the victim must interact with the authorization flow.
What information or actions does compromise enable?
An attacker can obtain OAuth connector session tokens and the associated provider account email. The disclosed tokens can be used to disconnect the victim's cloud storage connectors.