THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-m44r-7c5h-m6mj (high) — Medplum: Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage

[GHSA] GHSA-m44r-7c5h-m6mj (high) — Medplum: Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage

highgithub_advisoriesPublished 2026-08-17

GHSA-m44r-7c5h-m6mj Severity: high CVE: CVE-2026-53728

Medplum: Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage

## Summary

The external identity provider callback at `GET /auth/external` accepts attacker-controlled redirect URIs that only need to start with a registered client redirect URI, rather than matching exactly. After a successful external

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-m44r-7c5h-m6mj