Description
DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Attackers can obtain session tokens and provider account emails by acting as window.opener during OAuth authorization, then use tokens to disconnect victims' cloud storage connectors.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: OAuth token disclosure enabling unauthorized account disconnects
Action: Patch immediately
AI Analysis

Impact

DocsGPT versions up to 0.20.0 allow the application to post OAuth connector session tokens to a wildcard target origin in the callback‑status endpoint without validating the sender origin. An attacker can act as window.opener during OAuth authorization, intercept the token and the provider account email, and then use the token to disconnect the victim’s cloud storage connectors. This flaw is a CWE‑346 information‑exposure vulnerability and results in credential compromise and potential service disruption.

Affected Systems

All installations of arc53:DocsGPT through version 0.20.0 are affected. No other versions or editions are known to be impacted. The issue originates from the generic postMessage implementation used during the OAuth callback.

Risk and Exploitability

The CVSS score of 5.3 indicates medium severity, and the EPSS score is reported as < 1%. The vulnerability is not listed in CISA KEV. The likely attack requires the attacker to coerce the victim into opening an OAuth flow from a malicious context, becoming the window.opener of the DocsGPT authorization window. The attacker then captures the postMessage payload to obtain the session token and provider email, after which the token can be used to request a disconnection of the victim’s cloud connector, disabling file access and user data synchronization. Because the attacker must trick the user into visiting a malicious URL, the exploitation probability is low as indicated by the EPSS score.

Generated by OpenCVE AI on September 17, 2026 at 18:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade DocsGPT to a version where the postMessage target origin is validated and tokens are no longer sent to a wildcard origin.
  • If an upgrade is not immediately possible, modify the server to validate the Origin header before sending the token from the callback‑status endpoint, ensuring it is only sent to trusted origins.
  • As a temporary measure, restrict or block the callback‑status endpoint so that only internal or trusted applications can access it, limiting window.opener exposure.

Generated by OpenCVE AI on September 17, 2026 at 18:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Description DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Attackers can obtain session tokens and provider account emails by acting as window.opener during OAuth authorization, then use tokens to disconnect victims' cloud storage connectors.
Title DocsGPT through 0.20.0 OAuth Token Disclosure via Wildcard postMessage
First Time appeared Arc53
Arc53 docsgpt
Weaknesses CWE-346
CPEs cpe:2.3:a:arc53:docsgpt:*:*:*:*:*:*:*:*
Vendors & Products Arc53
Arc53 docsgpt
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:18.178Z

Reserved: 2026-09-14T21:55:44.093Z

Link: CVE-2026-91201

cve-icon Vulnrichment

Updated: 2026-09-18T17:17:00.617Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T23:19:00.783

Modified: 2026-09-23T17:17:44.793

Link: CVE-2026-91201

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:30:18Z

Weaknesses