CVE-2026-91201
Deferred Deferred - Pending Action

OAuth Session Token Exposure in DocsGPT

Vulnerability report for CVE-2026-91201, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-23

Assigner: VulnCheck

Description

DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Attackers can obtain session tokens and provider account emails by acting as window.opener during OAuth authorization, then use tokens to disconnect victims' cloud storage connectors.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-23
Generated
2026-10-05
AI Q&A
2026-09-15
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
docsgpt docsgpt 0.20.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-346 The product does not properly verify that the source of data or communication is valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

DocsGPT through 0.20.0 has an OAuth vulnerability where session tokens are posted to a wildcard origin without validating the sender's origin. Attackers can exploit this by acting as window.opener during OAuth authorization to steal session tokens and provider account emails, then use these tokens to disconnect victims' cloud storage connectors.

Detection Guidance

This vulnerability involves OAuth connector session tokens being exposed via a wildcard origin callback-status endpoint. Detection requires monitoring network traffic for OAuth callback interactions and checking if session tokens are transmitted to unauthorized origins. No specific commands are provided in the context.

Impact Analysis

If you use DocsGPT with OAuth connectors, an attacker could steal your session tokens and provider account emails. This could allow them to disconnect your cloud storage connectors, potentially leading to data loss or unauthorized access to your stored files.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's privacy rules. Organizations using DocsGPT may face compliance breaches, potential fines, and reputational damage due to compromised data integrity and confidentiality.

Mitigation Strategies

Upgrade DocsGPT to a version that fixes the OAuth callback-status endpoint origin validation issue. If no patch is available, disable OAuth connectors or restrict their use to trusted origins.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91201. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart