CVE-2026-91201
DocsGPT through 0.20.0 OAuth Token Disclosure via Wildcard postMessage
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Attackers can obtain session tokens and provider account emails by acting as window.opener during OAuth authorization, then use tokens to disconnect victims' cloud storage connectors.
| CWE | CWE-346 |
| Vendor | arc53 |
| Product | docsgpt |
| Published | Sep 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for arc53 docsgpt
Be the first to know when new medium vulnerabilities affecting arc53 docsgpt are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
Low
Affected Versions
arc53 / DocsGPT
0 โค 0.20.0
References
github.com: https://github.com/arc53/DocsGPT/issues/2766 github.com: https://github.com/arc53/DocsGPT github.com: https://github.com/arc53/DocsGPT/blob/c36b0af17037449f34449efa97da82becfc9492d/docsgpt/api/connector/routes.py#L515-L527 github.com: https://github.com/arc53/DocsGPT/blob/c36b0af17037449f34449efa97da82becfc9492d/frontend/src/components/ConnectorAuth.tsx#L57-L80 github.com: https://github.com/arc53/DocsGPT/blob/c36b0af17037449f34449efa97da82becfc9492d/docsgpt/api/connector/routes.py#L344-L366 vulncheck.com: https://www.vulncheck.com/advisories/docsgpt-through-0.20.0-oauth-token-disclosure-via-wildcard-postmessage
Credits
๐ George Chen