Cross-Origin Authorization Code Leak in Medplum Developer Platform
CVE-2026-53728

7.1HIGH

Key Information:

Vendor

Medplum

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-53728?

The Medplum Developer Platform is susceptible to a cross-origin authorization code leak due to improper handling of redirect URIs in its external identity provider callback. Specifically, it allows attacker-controlled redirect URIs that only need to begin with a registered client redirect URI. As a result, after a successful login with an external identity provider, sensitive authorization artifacts can be redirected to adversarial endpoints when the redirect URI is manipulated. This exploit stems from the server's trust in serialized JSON state values, enabling malicious actors to tamper with the redirect URI and potentially extract critical login information. This vulnerability has been addressed in version 5.1.6.

Affected Version(s)

medplum < 5.1.6

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.