PT-2026-95550 · Kyoo · Kyoo
CVE-2026-77386
·
Published
2026-09-18
·
Updated
2026-09-22
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Kyoo versions prior to 5.1.0
Description
An unauthenticated attacker can initiate an OpenID Connect (OIDC) login flow using a controlled
redirectUrl. The system stores this URL within the login state, and the endpoint '/auth/oidc/logged/{provider}' redirects the browser to this destination without validation, appending the provider, token, and error values. Since the one-use token is not bound to the session that started the login, an attacker can capture the token at their destination and exchange it via the '/auth/oidc/callback/{provider}' endpoint to hijack the victim's session.Recommendations
Update to version 5.1.0.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kyoo