PT-2026-24136 · Pocket Id · Pocket-Id

Byamb4

·

Published

2026-03-09

·

Updated

2026-03-25

·

CVE-2026-28512

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Pocket ID versions 2.0.0 through 2.4.0
Description A flaw in callback URL validation allowed crafted redirect uri values containing URL userinfo (@) to bypass legitimate callback pattern checks. If an attacker can trick a user into opening a malicious authorization link, the authorization code may be redirected to an attacker-controlled host. This issue affects an OpenID Connect (OIDC) provider, allowing users to authenticate with passkeys.
Recommendations Update to version 2.4.0 or later. As a workaround, reject callback URLs containing userinfo (@) at the reverse proxy or application policy level if feasible.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28512
GHSA-9H33-G3WW-MQFF
GO-2026-4653
SUSE-SU-2026:1042-1

Affected Products

Pocket-Id