CVE-2026-31381

Publication date

2026-03-20 13:02:07

Family

rapid7

State

PUBLISHED

Description

An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth callback URL.