CVE-2026-97325 | YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08 OAuth2 Client OAuth2ClientServiceImpl.java validOAuthClientFromCache redirect_uri

SecurityVulns

A vulnerability classified as problematic was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected by this vulnerability is the function validOAuthClientFromCache of the file yudao-module-system/src/main/java/cn/iocoder/yudao/module/system/service/oauth2/OAuth2ClientServiceImpl.java of the component OAuth2 Client. The manipulation of the argument redirect_uri results in open redirect.

This vulnerability is reported as CVE-2026-97325. The attack can be launched remotely. Moreover, an exploit is present.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More