On this page
Vulnerability Details
- Impact
- Account takeover (lab reproduction)
- Affected Systems
- Self-built OAuth 2.0 authorization server (Node.js lab)
Executive Summary
This is a lab case study of a well-known class of OAuth 2.0 bug: weak redirect_uri validation. I built a small authorization server that validates redirect URIs with a loose prefix check, then exploited it to send authorization codes to an attacker-controlled host and take over the victim’s account. The same pattern has shown up in real bug-bounty reports, which is why it’s worth understanding end to end.
Root Cause Analysis
The authorization server performed URI matching using loose regex string comparisons:
// Vulnerable URI Validation Routinefunction validateRedirectUri(requestedUri, registeredUris) { return registeredUris.some(uri => requestedUri.startsWith(uri));}Because startsWith was evaluated without proper host boundary checks, passing https://legit-site.com.attacker.com/callback satisfied the check.
Remediation Guidance
- Enforce exact matching for all registered
redirect_urivalues. - Mandate PKCE (Proof Key for Code Exchange) across all authorization code grants.