{"id":"CVE-2020-26938","aliases":["GHSA-4rg6-fm25-gc34"],"url":"https://o3.security/vulnerability/CVE-2020-26938","summary":"oauth2-server through 3.1.1 vulnerable to Open Redirect","details":"In oauth2-server (aka node-oauth2-server) through 3.1.1, the value of the redirect_uri parameter received during the authorization and token request is checked against an incorrect URI pattern (\"[a-zA-Z][a-zA-Z0-9+.-]+:\") before making a redirection. This allows a malicious client to pass an XSS payload through the redirect_uri parameter while making an authorization request. NOTE: this vulnerability is similar to CVE-2020-7741.","published":"2022-08-29T21:15:08.863Z","modified":"2026-07-08T23:35:15.068881Z","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"npm","name":"oauth2-server","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://tools.ietf.org/html/rfc3986#section-3"},{"type":"ADVISORY","url":"https://tools.ietf.org/html/rfc6749#section-3.1.2"},{"type":"REPORT","url":"https://github.com/oauthjs/node-oauth2-server/issues/637"},{"type":"EVIDENCE","url":"https://github.com/oauthjs/node-oauth2-server/blob/91d2cbe70a0eddc53d72def96864e2de0fd41703/lib/grant-types/authorization-code-grant-type.js#L143"},{"type":"EVIDENCE","url":"https://github.com/oauthjs/node-oauth2-server/blob/91d2cbe70a0eddc53d72def96864e2de0fd41703/lib/validator/is.js#L12"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-26938"},{"type":"PACKAGE","url":"https://github.com/oauthjs/node-oauth2-server"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T23:35:15.068881Z"}}