LOW GitHub

CVE-2026-42350

Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter

## Summary The Kargo UI reads a `redirectTo` query parameter on the `/login` and `/token-renew` routes and, following a successful OIDC authentication, uses its value as the destination for client-side navigation. The parameter is treated as a path string but is not constrained to targets within the UI's own origin. Protocol-relative values (e.g. `//attacker.example.com`) and values using a backslash prefix (e.g. `/\attacker.example.com`) are accepted and result in navigation to an external ori

Affected Products

References

Published: 2026-08-27 · Source: GitHub · Feed updated: 2026-08-27
This low severity vulnerability was published on 2026-08-27 via GitHub. Affected: go/github.com/akuity/kargo < 1.7.10, go/github.com/akuity/kargo >= 1.8.0, < 1.8.13, go/github.com/akuity/kargo >= 1.9.0, < 1.9.8 and 1 more.
vulnfeed aggregates 11337 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.