PT-2026-79114 · Unknown · Securedrop Client

CVE-2026-49996

·

Published

2026-08-20

·

Updated

2026-08-20

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SecureDrop Client versions prior to 1.3.1
Description A malicious SecureDrop Server can bypass the origin limitation of the securedrop-proxy by responding with cross-origin redirects. The SecureDrop Server is a dedicated physical machine that uses Tor hidden services for its Source and Journalist interfaces, and may allow remote SSH access via another Tor hidden service.
Recommendations Update to version 1.3.1.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49996
GHSA-6QXC-PCFG-V6QV

Affected Products

Securedrop Client