An OAuth redirect left the registered callback
An OAuth code is a bearer secret for one exchange. The useful note is whether the redirect stayed on the registered callback. This card does not repeat the redirect value.
- Original severity
- High (7 ~ 8.9) source-reported; not rescored by vulns.co
- Public source
- hackerone disclosure
- Program / vendor
- pixiv
- Product / surface
- OAuth authorization endpoint for booth login
- Weakness
- OAuth redirect validation
- Affected boundary
- The registered OAuth callback and a page the reporter controlled
- Disclosure date
- 2023-03-22
- Public status checked
- 2026-09-28
- Public attribution
- kuzu7shiki
What the evidence established
The disclosed report says the OAuth redirect target was not held to the registered callback, and an authorization code then reached a page the reporter controlled. The program resolved it.
Why the impact was credible
The source reported that an authorization code could be delivered outside the registered callback.
Durable engineering lesson
An OAuth code is a bearer secret for one exchange. The useful note is whether the redirect stayed on the registered callback. This card does not repeat the redirect value.
Control pattern
Accept only the exact registered redirect. Compare the full URL, not a prefix of the path.
Primary public disclosure
Upstream availability and wording can change. Public status was last checked 2026-09-28.