HackerOne Disclosed Reports - 2025-12-16

0 Replies, 186 Views

Logo
Low
resolved

Second-Order XSS via javascript protocol in MCP Server Portal Apps leads to ATO


Bug reported by Nishant was disclosed at December 16, 2025, 9:47 am   |   Cross-site Scripting (XSS) - Stored

The vulnerability in the MCP Server Portal Apps was caused by missing sanitization of the redirect_uri parameter, leading to a second-order XSS vulnerability. An attacker could craft a malicious redirect_uri containing JavaScript code, obtain a client_id for this URI, and reuse it when a victim had an active session on the /authorize endpoint to execute arbitrary JavaScript.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]

Messages In This Thread
HackerOne disclosed reports - 2025-12-16 - by hashXploiter - 12-17-2025, 12:30 PM



Users browsing this thread: 1 Guest(s)