๐Ÿ” CVE Alert

CVE-2026-47660

UNKNOWN 0.0

Pathling: Explicit oauthMetadataUrl in bulk-submit allows OAuth client credential exfiltration

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's bulk-submit operation allows an allowed submitter to supply an explicit `oauthMetadataUrl` parameter that is not validated against `pathling.bulkSubmit.allowableSources`. When present, the bulk-submit OAuth flow trusts metadata and the returned `token_endpoint` from the caller-chosen location, then builds outbound OAuth client authentication directly from the submitter's stored credentials. This is fixed in Pathling Server 2.0.0.

CWE CWE-522 CWE-918
Vendor aehrc
Product pathling
Published Aug 7, 2026
Last Updated Aug 7, 2026
Stay Ahead of the Next One

Get instant alerts for aehrc pathling

Be the first to know when new unknown vulnerabilities affecting aehrc pathling are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

aehrc / pathling
< 2.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/aehrc/pathling/security/advisories/GHSA-245h-c573-9vr5