HIGH 7.1 GitHub

CVE-2026-53728

Medplum: Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage

## Summary The external identity provider callback at `GET /auth/external` accepts attacker-controlled redirect URIs that only need to start with a registered client redirect URI, rather than matching exactly. After a successful external IdP login, the server appends Medplum `login` and `code` values to that attacker-supplied URL and issues a redirect. Because the external login request `state` is serialized as raw JSON and later trusted by the callback, an attacker who can tamper with `state.

Affected Products

References

Published: 2026-08-17 · Source: GitHub · Feed updated: 2026-08-17
This high severity vulnerability with a CVSS score of 7.1 was published on 2026-08-17 via GitHub. Affected: npm/@medplum/core <= 5.1.5.
vulnfeed aggregates 11698 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.