PT-2026-47239 · Unknown · Hsweb-Framework

·

CVE-2026-11477

·

Published

2026-06-08

·

Updated

2026-06-08

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions hs-web hsweb-framework versions prior to 5.0.2
Description An open redirect issue exists in the OAuth2 Client component. A remote attacker can manipulate the OAuth2Client() function within the file hsweb-authorization/hsweb-authorization-oauth2/src/main/java/org/hswebframework/web/oauth2/server/OAuth2Client.java to redirect users to an arbitrary external site.
Recommendations Apply patch c2882679a9125cea52678151af5ae213cbd52579 to resolve the issue. As a temporary workaround, restrict access to the OAuth2Client() function until the patch is applied.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11477
GHSA-FXR3-GVM4-M8VC

Affected Products

Hsweb-Framework