Skip to content

Pocket ID: OIDC authorization code validation uses AND instead of OR, allowing cross-client token exchange

High severity GitHub Reviewed Published Mar 7, 2026 in pocket-id/pocket-id • Updated Mar 10, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts