THREAT OPS › Threat News › [GHSA] GHSA-xwmw-prc4-v3cr (high) — Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion
[GHSA] GHSA-xwmw-prc4-v3cr (high) — Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion
GHSA-xwmw-prc4-v3cr Severity: high CVE: None
Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion
## Summary
In affected versions, an unauthenticated attacker could register an OAuth client with an arbitrary external redirect URI, and the authorization flow would auto-complete without a consent screen. If a logged-in victim visited a crafted authorization URL,
Original source: https://github.com/advisories/GHSA-xwmw-prc4-v3cr