PT-2026-95550 · Kyoo · Kyoo

CVE-2026-77386

·

Published

2026-09-18

·

Updated

2026-09-22

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kyoo versions prior to 5.1.0
Description An unauthenticated attacker can initiate an OpenID Connect (OIDC) login flow using a controlled redirectUrl. The system stores this URL within the login state, and the endpoint '/auth/oidc/logged/{provider}' redirects the browser to this destination without validation, appending the provider, token, and error values. Since the one-use token is not bound to the session that started the login, an attacker can capture the token at their destination and exchange it via the '/auth/oidc/callback/{provider}' endpoint to hijack the victim's session.
Recommendations Update to version 5.1.0.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77386
GHSA-XHG6-V78P-XF44

Affected Products

Kyoo