Skip to content

xomnibot@lab:~/research/oauth-redirect-uri-bypass-case-study$

Case Study: OAuth 2.0 Redirect URI Bypass & Account Takeover

Reproducing a classic OAuth 2.0 redirect_uri validation flaw in a self-built lab: how loose prefix matching leaks authorization codes, and how to fix it.

1 min read
On this page

Vulnerability Details

Impact
Account takeover (lab reproduction)
Affected Systems
Self-built OAuth 2.0 authorization server (Node.js lab)

Executive Summary

This is a lab case study of a well-known class of OAuth 2.0 bug: weak redirect_uri validation. I built a small authorization server that validates redirect URIs with a loose prefix check, then exploited it to send authorization codes to an attacker-controlled host and take over the victim’s account. The same pattern has shown up in real bug-bounty reports, which is why it’s worth understanding end to end.


Root Cause Analysis

The authorization server performed URI matching using loose regex string comparisons:

// Vulnerable URI Validation Routine
function validateRedirectUri(requestedUri, registeredUris) {
return registeredUris.some(uri => requestedUri.startsWith(uri));
}

Because startsWith was evaluated without proper host boundary checks, passing https://legit-site.com.attacker.com/callback satisfied the check.


Remediation Guidance

  1. Enforce exact matching for all registered redirect_uri values.
  2. Mandate PKCE (Proof Key for Code Exchange) across all authorization code grants.