A vulnerability exists in Medplum, a healthcare developer platform, affecting versions 4.1.10 through 5.1.6. The /oauth2/register endpoint could inadvertently return the client_secret of preconfigured OAuth clients defined in the defaultOAuthClients server configuration. This exposure occurs when a matching redirect_uri is provided by an attacker or unauthorized party. The leaked client secrets could allow unauthorized access to OAuth-protected resources within healthcare applications built on the platform. This poses a significant risk given the sensitive nature of healthcare data. The vulnerability has been addressed and patched in version 5.1.7. Users are strongly advised to upgrade to the patched version immediately. No workaround details are provided beyond upgrading.