Junglewise Threat Intelligence

CVE-2025-54066: DiracX-Web open redirect on login page

CVE-2025-54066 · Severity: low · CVSS 3.1 · Published 2025-07-17

Vendors: npm.

Executive brief

DiracX-Web is a web-based authentication component used in the DIRAC distributed computing framework. The login page contains an unvalidated redirect parameter that allows attackers to forge URLs redirecting authenticated users to arbitrary external websites. This vulnerability enables phishing attacks and credential theft by tricking users into entering their credentials on fake login pages.

Technical details

The vulnerability is an open redirect (CWE-601) in the DiracX-Web login page's redirect parameter. The redirect URI is accepted without validation and can be set to any arbitrary URL. An attacker can exploit this by crafting a malicious URL with parameter pollution to hide the malicious redirect target, then sending it to authenticated users. The attack vector is network-based and requires user interaction (the user must click the malicious link). The vulnerability allows confidentiality impact through phishing and credential harvesting. A patch is available in version 0.1.0-a8 of @dirac-grid/diracx-web-components.

Affected products

  • DIRACGrid @dirac-grid/diracx-web-components 0.1.0-a7 and earlier; fixed in 0.1.0-a8

Timeline

  • 2025-07-17: disclosed: Vulnerability published in GitHub Security Advisory
  • 2025-07-17: patched: Fix released in version 0.1.0-a8

References