LOW GitHub
CVE-2026-42350
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter
## Summary
The Kargo UI reads a `redirectTo` query parameter on the `/login` and `/token-renew` routes and, following a successful OIDC authentication, uses its value as the destination for client-side navigation. The parameter is treated as a path string but is not constrained to targets within the UI's own origin. Protocol-relative values (e.g. `//attacker.example.com`) and values using a backslash prefix (e.g. `/\attacker.example.com`) are accepted and result in navigation to an external ori
Affected Products
- go/github.com/akuity/kargo < 1.7.10
- go/github.com/akuity/kargo >= 1.8.0, < 1.8.13
- go/github.com/akuity/kargo >= 1.9.0, < 1.9.8
- go/github.com/akuity/kargo >= 1.10.0, < 1.10.2
References
- https://github.com/advisories/GHSA-g7gw-m874-7rmf
- https://github.com/akuity/kargo/security/advisories/GHSA-g7gw-m874-7rmf
- https://nvd.nist.gov/vuln/detail/CVE-2026-42350
- https://github.com/akuity/kargo/commit/0b89215740e93d18f1ab2187f6f9733137f9d00f
This low severity vulnerability was published on 2026-08-27 via GitHub. Affected: go/github.com/akuity/kargo < 1.7.10, go/github.com/akuity/kargo >= 1.8.0, < 1.8.13, go/github.com/akuity/kargo >= 1.9.0, < 1.9.8 and 1 more.
vulnfeed aggregates 11337 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.