CVE-2026-91201 is a medium-severity vulnerability in DocsGPT through 0.20.0, where OAuth connector session tokens are posted to a wildcard target origin in the callback-status endpoint without validating sender origin. This allows attackers to obtain session tokens and provider account emails by acting as window.opener during OAuth authorization. Defenders should assess their exposure and prioritize verif [truncated]
CVE-2026-13483 is a vulnerability in arc53 DocsGPT versions up to 0.18.0. The issue lies in the encrypt_credentials function within the application/security/encryption.py file, which is part of the Credential Storage component. This vulnerability leads to insufficient verification of data authenticity. An attacker can initiate the attack remotely, but the complexity of the attack is high and its exploitab [truncated]