Ad

CVE-2026-28513

HIGH CVSS 3.1: 7.1 EPSS 0.01%
Updated Mar 13, 2026
Pocket-Id
Parameter Value
CVSS 7.1 (HIGH)
Affected Versions before 2.4.0
Fixed In 2.4.0
Type CWE-863 (Incorrect Authorization)
Vendor Pocket-Id
Public PoC Yes

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.4.0, the OIDC token endpoint rejects an authorization code only when both the client ID is wrong and the code is expired. This allows cross-client code exchange and expired code reuse.

This vulnerability is fixed in 2.4.0.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Pocket-Id Pocket_Id
cpe:2.3:a:pocket-id:pocket_id:*:*:*:*:*:*:*:*
2.4.0