{"id":"CVE-2026-54072","summary":"Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to attacker-controlled URL","details":"Authorizer is an open-source, self-hostable authentication and authorization server. Prior to version 2.2.1, the `/authorize` endpoint accepts any `redirect_uri` without validating it against `AllowedOrigins`. When `response_type=token` or `response_type=id_token`, the server appends `access_token`, `id_token`, and `refresh_token` as query parameters and issues a 302 redirect to the attacker-supplied URL. An unauthenticated attacker can obtain the required `client_id` from the public `/graphql?query={meta{client_id}}` endpoint. A partial fix was applied in v2.0.1 to other handlers (`oauth_login`, `verify_email`, `magic_link_login`, `forgot_password`, `invite_members`, `oauth_callback`) but `/authorize` was not included. Version 2.2.1 contains a more complete fix.","aliases":["GHSA-h29v-hj44-q8cv","GO-2026-5959"],"modified":"2026-09-13T03:30:17.589892540Z","published":"2026-09-11T18:41:52.963Z","related":["openSUSE-SU-2026:21483-1"],"database_specific":{"cwe_ids":["CWE-601"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54072.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54072.json"},{"type":"ADVISORY","url":"https://github.com/authorizerdev/authorizer/security/advisories/GHSA-h29v-hj44-q8cv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54072"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/authorizerdev/authorizer","events":[{"introduced":"0"},{"fixed":"1726717485db6387a98019e1196dd5a233dfb7f4"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.2.1"}],"source":"AFFECTED_FIELD"}}],"versions":["2.2.1-rc.2","2.2.1-rc.1","2.2.1-rc.0","2.2.0","2.1.0","2.0.1","2.0.0","2.0.0-rc.6","2.0.0-rc.5","2.0.0-rc.4","2.0.0-rc.3","2.0.0-rc.2","2.0.0-rc.1","1.4.4","1.4.3","1.4.2","1.4.1","1.4.0","1.3.8","1.3.7","1.3.6","1.3.5","1.3.4","1.3.2","1.3.1","1.3.0","1.2.4","1.2.3","1.3.0-beta.0","1.2.2","1.2.1","1.1.33","1.2.0","1.1.71","1.1.70","1.1.69","1.1.68","1.1.67","1.1.66","1.1.65","1.1.52","1.1.64","1.1.63","1.1.62","1.1.61","1.1.60","1.1.59","1.1.58","1.1.57","1.1.56","1.1.55","1.1.54","1.1.53","1.1.51","1.1.50","1.1.49","1.1.35","1.1.48","1.1.47","1.1.46","1.1.45","1.1.44","1.1.43","1.1.42","1.1.41","1.1.40","1.1.39","1.1.38","1.1.37","1.1.36","1.1.34","1.1.32","1.1.31","1.1.30","1.1.29","1.1.28-rc.5","1.1.28","1.1.28-rc.4","1.1.28-rc.3","1.1.28-rc.2","1.1.28-rc.1","1.1.27","1.1.26","1.1.25-beta.0","1.1.25","1.1.24","1.1.23","1.1.22","1.1.21","1.1.21.beta.5","1.1.21.beta.3","1.1.20","1.1.20-beta.0","1.1.9","1.1.8","1.1.7","1.1.6","1.1.5","1.1.4","1.1.3","1.1.2","1.1.1","1.1.0","1.0.1","1.0.0","0.39.0","0.38.0","0.36.0","0.37.0","0.35.0","0.34.0","0.33.0","0.32.0","0.31.0","0.30.0","0.28.0","0.27.0","0.26.0","0.25.0","0.25.0-beta.2","0.25.0-beta.1","0.24.0-beta.1","0.24.0","0.23.0","0.22.2","0.22.1","0.22.0","0.21.0","0.20.0","0.19.0","0.18.1","0.18.0","0.17.0","0.16.0","0.14.0","0.15.0","0.13.1","0.13.0","0.12.0","0.11.0","0.10.3","0.10.2","0.10.1","0.10.0","0.9.2","0.9.1","0.9.0","0.8.5","0.8.4","0.8.3","0.8.2","0.8.1","0.8.0","0.7.0","0.6.1","0.6.0","0.5.0","0.4.0","0.3.0","0.2.0","0.1.0","0.1.0-beta.43","0.1.0-beta.42","0.1.0-beta.41","0.1.0-beta.40","0.1.0-beta.38","0.1.0-beta.37","0.1.0-beta.36","0.1.0-beta.35","0.1.0-beta.34","0.1.0-beta.33","0.1.0-beta.32","0.1.0-beta.31","0.1.0-beta.30","0.1.0-beta.29","0.1.0-beta.28","0.1.0-beta.27","0.1.0-beta.26","0.1.0-beta.25","0.1.0-beta.24","0.1.0-beta.23","0.1.0-beta.22","0.1.0-beta.21","0.1.0-beta.19","0.1.0-beta.18","0.1.0-beta.17","0.1.0-beta.16","0.1.0-alpha31","0.1.0-alpha30","0.1.0-alpha29","0.1.0-alpha28","0.1.0-alpha27","0.1.0-alpha26","0.1.0-alpha25","0.1.0-alpha24","0.1.0-alpha23","0.1.0-alpha22","0.1.0-alpha21","0.1.0-alpha20","0.1.0-alpha19","0.1.0-alpha18","0.1.0-alpha17","0.1.0-alpha16","0.1.0-alpha15","0.1.0-alpha14","0.1.0-alpha13","0.1.0-alpha12","0.1.0-alpha11","0.1.0-alpha10","0.1.0-alpha9","0.1.0-alpha8","0.1.0-alpha7","0.1.0-alpha6","0.1.0-alpha5","0.1.0-alpha4","0.1.0-alpha3","0.1.0-alpha2","0.1.0-alpha1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54072.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"}]}