Octo STS Unauthenticated SSRF by abusing fields in OpenID Connect tokens
GHSA-h3qp-hwvr-9xcq · CVE-2025-52477 · GO-2025-3779
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Summary
Octo-STS versions before v0.5.3 are vulnerable to unauthenticated SSRF by abusing fields in OpenID Connect tokens. Malicious tokens were shown to trigger internal network requests which could reflect error logs with sensitive information.
Please upgrade to v0.5.3 to resolve this issue. This version includes patch sets to sanitize input and redact logging.
Many thanks to @vicevirus for reporting this issue and for assisting with remediation review.
References
References
- WEB https://github.com/octo-sts/app/security/advisories/GHSA-h3qp-hwvr-9xcq
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2025-52477
- WEB https://github.com/octo-sts/app/commit/0f177fde54f9318e33f0bba6abaea9463a7c3afd
- WEB https://github.com/octo-sts/app/commit/b3976e39bd8c8c217c0670747d34a4499043da92
- PACKAGE https://github.com/octo-sts/app
Ready to move
Start Securing
Free, no credit card | First findings in minutes