Vendor
Coroot versions 1.20.2 through 1.24.5 are vulnerable to unauthenticated OAuth dynamic client registration, allowing attackers to hijack user sessions via open redirect and authorization code theft.