| Summary | Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExchangeToken function in object/token_oauth.go validates JWT signatures but does not verify that the token's user belongs to the same organization as the target application. This can result in privilege escalation across organizational boundaries. |
|---|---|
| Publication Date | May 29, 2026, 2:16 a.m. |
| Registration Date | May 29, 2026, 4:15 a.m. |
| Last Update | May 29, 2026, 3 a.m. |