PT-2026-81481 · Coroot · Coroot

·

CVE-2026-79786

·

Published

2026-08-25

·

Updated

2026-08-28

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Coroot (affected versions not specified)
Description An unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without validation. This allows attackers to register clients that point to hosts under their control. By sending authorization URLs to signed-in users, attackers can capture authorization codes after consent is granted and exchange them for access tokens to hijack MCP sessions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79786

Affected Products

Coroot