PT-2026-71978 · Chi · Chi
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
chi versions prior to v5.2.2
Description
The
RedirectSlashes() middleware function uses the Host header to construct redirect URLs. An attacker can manipulate this header to redirect users to arbitrary external hosts, which can be used to facilitate phishing attacks and the theft of credentials.Recommendations
Update to version v5.2.2 or later.
As a temporary workaround, consider disabling the
RedirectSlashes() middleware function until the update is applied.Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chi