PT-2026-57044 · Openrun · Openrun

CVE-2026-55252

·

Published

2026-07-09

·

Updated

2026-07-30

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions openrun (affected versions not specified)
Description Restrictions on redirect URLs can be bypassed, leading to open redirect attacks. The issue occurs because the validation logic only verifies that the host and schema of the redirect URL match the current website, subsequently using only the path part for the redirection. An attacker can bypass this by providing a URL where the path begins with //, such as http://127.0.0.1:25222//fushuling.com. Browsers interpret paths starting with // as protocol-relative URLs, which redirects the user to an external domain. This is triggered via the Referer header.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55252
GHSA-H5G6-XMH4-HC37
GO-2026-5956
OPENSUSE-SU-2026:21483-1

Affected Products

Openrun