Pretty sure this is based on one of those "login with Facebook" oAuth apps where your just using Facebook as the IDP. They were probably using the token to lookup the email address (via 'profile' scope) but not validating that the token originated from their connected app. Also, this is why the "client secret" needs to be kept secret (so a hacker can't trick users to login via your connected app)
the jwt isnt tampered with. imgur servers did not validate the decoded payload matched their fb app id. it says in the docs be sure too match on the app id because fb isn't going through the ceremony of checking that your oAuth key is registered to a specific app id and therefore only valid together. app id is considered arbitrary payload metadata in this sense.
This problem/attack is called "confused deputy". It's surprisingly hard to find a link that correctly explains the problem and its mitigations. This one is correct but not very verbose:
https://medium.com/@fhbro/confused-deputy-c9e75eb7df00#8edf