Impact
Coroot’s MCP OAuth dynamic client registration endpoint allows any syntactically valid redirect URI to be registered without validation. An attacker can register a client that redirects to an attacker‑controlled host. When a legitimate user consents to the authorization request, the authorization code is sent to the attacker’s site and can be traded for an access token, enabling hijacking of the user’s MCP session.
Affected Systems
The vulnerability affects Coroot versions 1.20.2 through 1.24.5. The impacted product is the Coroot web application exposed via the MCP OAuth API.
Risk and Exploitability
The CVSS score of 7 indicates a high severity vulnerability. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by registering a malicious client and luring users to approve an authorization flow, a process that requires no additional authentication. The attack vector is likely a malicious redirect URI, followed by a user‑initiated approval click.
OpenCVE Enrichment