CVE-2026-55834: Pocket-Id

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to services. From 2.6.0 until 2.9.0, frontend/src/routes/authorize/+page.ts reads the redirect_uri query parameter and frontend/src/routes/authorize/+page.svelte uses the raw callbackURL in redirectWithError when prompt=none cannot complete silent authorization. The client-side path only blocks javascript and data schemes and does not invoke the backend callback allow-list validation, so an unauthenticated attacker who knows a valid client_id can redirect a victim browser to an arbitrary HTTP or HTTPS origin for phishing or OIDC error and state smuggling. This issue is fixed in version 2.9.0.

Affected products

  • Pocket-Id Pocket-Id: from 2.6.0, before 2.9.0 (fixed in 2.9.0)

Published 2026-08-28. Last modified 2026-09-09.