MEDIUM 5.7 NVD

CVE-2026-59788

The email media type OAuth form passes the Authorization endpoint value to window.open() without validating the URL scheme, so a javascript: URL is executed in

The email media type OAuth form passes the Authorization endpoint value to window.open() without validating the URL scheme, so a javascript: URL is executed in the browser. This means a crafted media type configuration, deliverable as an import file, runs arbitrary JavaScript as the Super Admin who grants consent.

References

Published: 2026-10-05 · Source: NVD · Feed updated: 2026-10-05
This medium severity vulnerability with a CVSS score of 5.7 was published on 2026-10-05 via NVD.
vulnfeed aggregates 7640 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.