We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Sonos api.sonos.com through 2025-04-21, when the /login/v3/oauth endpoint is used, accepts a redirect_uri containing userinfo in the authority component, which is not consistent with RFC 6819 section 5.2.3.5. An authorization code may be sent to an attacker-controlled destination. This might have further implications in conjunction with "Decompiling the app revealed a hardcoded secret."
Reserved 2025-04-19 | Published 2025-04-21 | Updated 2025-04-21 | Assigner mitreCWE-647 Use of Non-Canonical URL Paths for Authorization Decisions
github.com/...ity-reports/blob/main/CVE-2025-43916/detail.md
Support options