OAuth Token Disclosure in DocsGPT Affects Multiple User Accounts
CVE-2026-91201

5.3MEDIUM

Key Information:

Vendor

Arc53

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-91201?

The DocsGPT application, up to version 0.20.0, exhibits a vulnerability in its OAuth connector that allows session tokens to be posted to a wildcard target origin without validating the sender's origin. This oversight can be exploited by malicious actors who utilize the window.opener object during OAuth authorization. By doing so, they can extract sensitive information such as session tokens and associated provider account emails, potentially enabling them to disconnect victims' cloud storage connectors and gain unauthorized access to user data.

Affected Version(s)

DocsGPT 0 <= 0.20.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.