CVE-2026-91201
Last modified
CVE-2026-91201 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Attackers can obtain session tokens and provider account emails by acting as window.opener during OAuth authorization, then use tokens to disconnect victims' cloud storage connectors..
Description
DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Attackers can obtain session tokens and provider account emails by acting as window.opener during OAuth authorization, then use tokens to disconnect victims' cloud storage connectors.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| arc53 | DocsGPT | <= 0.20.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-91201?
How severe is CVE-2026-91201?
How do I fix CVE-2026-91201?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-9119Heap buffer overflow in WebRTC in Google Chrome on prior to …8.8
- CVE-2026-91197Flowable flowable-engine through 8.0.0 contains an XML exter…6.5
- CVE-2026-91198GrowthBook through 5.0.1 returns unredacted fact table defin…5.3
- CVE-2026-91199Refly through 1.1.0 contains a server-side request forgery v…5
- CVE-2026-9120Use after free in WebRTC in Google Chrome prior to 148.0.777…8.8
- CVE-2026-91200DevSpace through 6.3.21 fails to reject parent-directory seg…8.8
- CVE-2026-9121Out of bounds read in GPU in Google Chrome on prior to 148.0…8.8
- CVE-2026-9122Out of bounds read in GPU in Google Chrome on Mac prior to 1…6.5
- CVE-2026-9123Heap buffer overflow in Chromecast in Google Chrome on Andro…7.5
- CVE-2026-9124Insufficient validation of untrusted input in Input in Googl…5.3
- CVE-2026-9125The Presto Player plugin for WordPress is vulnerable to Stor…6.4
- CVE-2026-9126Use after free in DOM in Google Chrome on prior to 148.0.777…8.8
Are you affected by CVE-2026-91201?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
