VYPR

medplum

by Medplum

Source repositories

CVEs (2)

  • CVE-2026-49120HigJun 2, 2026
    risk 0.48cvss 8.5epss 0.00

    Medplum before 5.1.14 contains a server-side request forgery vulnerability in the subscription worker that allows authenticated users to perform unauthorized internal network requests by creating FHIR Subscription resources with arbitrary endpoint URLs. Attackers can point…

  • CVE-2026-53728higAug 17, 2026
    risk 0.38cvss epss

    ## Summary The external identity provider callback at `GET /auth/external` accepts attacker-controlled redirect URIs that only need to start with a registered client redirect URI, rather than matching exactly. After a successful external IdP login, the server appends Medplum…