Junglewise Threat Intelligence

CVE-2026-10839: Password Manager open redirection in authentication system

CVE-2026-10839 · Severity: info · CVSS 5.1 · Published 2026-06-17

Technologies: eusonlito (Github) Password Manager.

Executive brief

Password Manager, an application used to store and manage credentials for various services, is vulnerable to an open redirection flaw. An attacker can trick users into visiting a malicious website by manipulating the web addresses generated by the application during the login process. This could be used in phishing campaigns to steal user information or deliver malware by making a malicious link appear to come from a trusted source.

Technical details

An open redirection vulnerability (CWE-601) exists in the authentication system of Password Manager due to insufficient validation of the X-Forwarded-Host HTTP header. By supplying a manipulated value in this header, a remote attacker can influence the URLs generated by the application. When an authenticated user completes a login or interacts with specific interface elements, they may be redirected to an attacker-controlled domain. This vulnerability requires user interaction (clicking a link) and can be leveraged for phishing or credential harvesting. The issue was addressed in the update released on August 7, 2025.

Affected products

  • eusonlito (Github) Password Manager versions prior to August 7, 2025

Timeline

  • 2025-08-07: patched: Vulnerabilities fixed by the development team.
  • 2026-05-06: disclosed: Initial disclosure by INCIBE-CERT.
  • 2026-06-17: advisory: CVE published in the National Vulnerability Database (NVD).

References