Cross-Origin Authorization Code Leak in Medplum Developer Platform
CVE-2026-53728
7.1HIGH
What is CVE-2026-53728?
The Medplum Developer Platform is susceptible to a cross-origin authorization code leak due to improper handling of redirect URIs in its external identity provider callback. Specifically, it allows attacker-controlled redirect URIs that only need to begin with a registered client redirect URI. As a result, after a successful login with an external identity provider, sensitive authorization artifacts can be redirected to adversarial endpoints when the redirect URI is manipulated. This exploit stems from the server's trust in serialized JSON state values, enabling malicious actors to tamper with the redirect URI and potentially extract critical login information. This vulnerability has been addressed in version 5.1.6.
Affected Version(s)
medplum < 5.1.6
