HackerOne Disclosed Reports - 2025-12-16

0 Replies, 181 Views

Logo
Low
resolved

Second-Order XSS via javascript protocol in MCP Server Portal Apps leads to ATO


Bug reported by Nishant was disclosed at December 16, 2025, 9:47 am   |   Cross-site Scripting (XSS) - Stored

The vulnerability in the MCP Server Portal Apps was caused by missing sanitization of the redirect_uri parameter, leading to a second-order XSS vulnerability. An attacker could craft a malicious redirect_uri containing JavaScript code, obtain a client_id for this URI, and reuse it when a victim had an active session on the /authorize endpoint to execute arbitrary JavaScript.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]



Users browsing this thread: 1 Guest(s)