Cross-site scripting in oauthlib - CVE-2026-49264
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript in a client application's origin.
The vulnerability exists due to improper neutralization of input during web page generation in the RevocationEndpoint when processing JSONP revocation requests with attacker-controlled callback parameters. A remote attacker can supply a crafted callback parameter to execute arbitrary JavaScript in a client application's origin.
The JSONP feature is disabled by default and exploitation requires a browser page to load the response as JSONP.