Pocket ID OIDC Provider Refresh Token Authorization Bypass Vulnerability

Vulnerability

A vulnerability in Pocket ID's OIDC provider allows refresh tokens to be misused after authorization has been revoked, accounts disabled, or clients removed from groups. This issue arises because the 'createTokenFromRefreshToken' function, prior to version 2.6.0, validated the refresh token's integrity but failed to check the user's current authorization status before issuing new tokens. As a result, clients could indefinitely refresh tokens after authorization revocation, disabled accounts could still use refresh tokens, and group restrictions could be bypassed.

Impact

This vulnerability creates a significant security risk by allowing unauthorized access to user identity data and downstream services. It undermines authorization revocation, account disabling, and group-based access controls, creating potential backdoors in sensitive environments.

Reproduction

The vulnerability can be reproduced by obtaining a refresh token through the standard OIDC authorization flow, then revoking authorization, disabling the user account, or removing the user from a restricted group. Despite these actions, the refresh token remains valid and can be used to obtain new access tokens, including sensitive identity information.

Remediation

Users should update to Pocket ID version 2.6.0 or later, where this vulnerability has been fixed.

Added: May 12, 2026, 3:31 PM
Updated: May 12, 2026, 3:31 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
6.2
remediation
0.0
relevance
8.1
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.