CVE-2026-54072
Description
Authorizer is an open-source, self-hostable authentication and authorization server. Prior to version 2.2.1, the /authorize endpoint accepts any redirect_uri without validating it against AllowedOrigins. When response_type=token or response_type=id_token, the server appends access_token, id_token, and refresh_token as query parameters and issues a 302 redirect to the attacker-supplied URL. An unauthenticated attacker can obtain the required client_id from the public /graphql?query={meta{client_id}} endpoint. A partial fix was applied in v2.0.1 to other handlers (oauth_login, verify_email, magic_link_login, forgot_password, invite_members, oauth_callback) but /authorize was not included. Version 2.2.1 contains a more complete fix.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/authorizerdev/authorizerGo | < 0.0.0-20260409051328-bd3f5baf6d3d | 0.0.0-20260409051328-bd3f5baf6d3d |
Affected products
2- osv-coordsRange: < 0.0.20260723T184607-160000.1.1
- Range: <2.2.1
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.