vulns.co
/
GKData.io MCP

Back to Reports

An OAuth redirect left the registered callback

An OAuth code is a bearer secret for one exchange. The useful note is whether the redirect stayed on the registered callback. This card does not repeat the redirect value.

Editorial decision card. This page links to a source-verified public disclosure and contains only original defensive analysis. It does not mirror upstream HTML, payloads, attachments, private submissions, or exploit steps.
Original severity
High (7 ~ 8.9) source-reported; not rescored by vulns.co
Public source
hackerone disclosure
Program / vendor
pixiv
Product / surface
OAuth authorization endpoint for booth login
Weakness
OAuth redirect validation
Affected boundary
The registered OAuth callback and a page the reporter controlled
Disclosure date
2023-03-22
Public status checked
2026-09-28
Public attribution
kuzu7shiki

What the evidence established

The disclosed report says the OAuth redirect target was not held to the registered callback, and an authorization code then reached a page the reporter controlled. The program resolved it.

Why the impact was credible

The source reported that an authorization code could be delivered outside the registered callback.

Durable engineering lesson

An OAuth code is a bearer secret for one exchange. The useful note is whether the redirect stayed on the registered callback. This card does not repeat the redirect value.

Control pattern

Accept only the exact registered redirect. Compare the full URL, not a prefix of the path.

Primary public disclosure

Read the original source ↗

Upstream availability and wording can change. Public status was last checked 2026-09-28.