Executive brief
LemonLDAP::NG is an open-source single sign-on (SSO) solution used to manage user authentication and access control. A security flaw in its SAML cookie handling component allows attackers to redirect users to malicious websites. This could be used in phishing campaigns to trick employees into providing credentials to a fake login page that appears legitimate.
Technical details
An open redirect vulnerability (CWE-601) exists in LemonLDAP::NG versions up to and including 2.23.0. The flaw is located in the SAML Common Domain Cookie (CDC) Endpoint within the 'lemonldap-ng-portal/lib/Lemonldap/NG/Portal/CDC.pm' library. By manipulating the 'url' argument, a remote, unauthenticated attacker can craft a link that redirects a victim to an arbitrary external domain. While the vulnerability does not directly allow for data exfiltration, it is a primary vector for phishing and credential harvesting attacks. As of the advisory date, the vendor has not responded to the disclosure.
Affected products
- LemonLDAP::NG Project lemonldap-ng up to 2.23.0
Timeline
- 2026-06-21: disclosed
- 2026-06-21: advisory