THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-xwmw-prc4-v3cr (high) — Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion

[GHSA] GHSA-xwmw-prc4-v3cr (high) — Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion

medgithub_advisoriesPublished 2026-09-18

GHSA-xwmw-prc4-v3cr Severity: high CVE: None

Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion

## Summary

In affected versions, an unauthenticated attacker could register an OAuth client with an arbitrary external redirect URI, and the authorization flow would auto-complete without a consent screen. If a logged-in victim visited a crafted authorization URL,

Original source: https://github.com/advisories/GHSA-xwmw-prc4-v3cr