PT-2026-24136 · Pocket Id · Pocket-Id

Byamb4

·

Publicado

2026-03-09

·

Atualizado

2026-03-25

·

CVE-2026-28512

CVSS v3.1

7.1

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Pocket ID versions 2.0.0 through 2.4.0
Description A flaw in callback URL validation allowed crafted redirect uri values containing URL userinfo (@) to bypass legitimate callback pattern checks. If an attacker can trick a user into opening a malicious authorization link, the authorization code may be redirected to an attacker-controlled host. This issue affects an OpenID Connect (OIDC) provider, allowing users to authenticate with passkeys.
Recommendations Update to version 2.4.0 or later. As a workaround, reject callback URLs containing userinfo (@) at the reverse proxy or application policy level if feasible.

Exploit

Correção

Open Redirect

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-28512
GHSA-9H33-G3WW-MQFF
GO-2026-4653
SUSE-SU-2026:1042-1

Produtos afetados

Pocket-Id