PT-2026-57044 · Openrun · Openrun
CVE-2026-55252
·
Published
2026-07-09
·
Updated
2026-07-30
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
openrun (affected versions not specified)
Description
Restrictions on redirect URLs can be bypassed, leading to open redirect attacks. The issue occurs because the validation logic only verifies that the host and schema of the redirect URL match the current website, subsequently using only the path part for the redirection. An attacker can bypass this by providing a URL where the path begins with
//, such as http://127.0.0.1:25222//fushuling.com. Browsers interpret paths starting with // as protocol-relative URLs, which redirects the user to an external domain. This is triggered via the Referer header.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openrun