Junglewise Threat Intelligence

CVE-2026-49820: Probo open redirect bypass via path normalization in saferedirect

CVE-2026-49820 · Severity: medium · CVSS 4.7 · Published 2026-06-30

Vendors: Go.

Executive brief

Probo, a platform used for authentication and session management, contains a flaw in how it validates web addresses during login and session transfers. An attacker can create a malicious link that appears to belong to a trusted Probo domain but actually redirects the user to a fraudulent website. This can be used in phishing attacks to steal user credentials or distribute malware by exploiting the user's trust in the original domain.

Technical details

An open redirect vulnerability exists in Probo's `saferedirect` package due to improper validation of relative paths. The validator incorrectly only inspected the second character of a path; consequently, a payload like `/../\evil.com` would pass validation. When processed by Go's `http.Redirect`, the path is normalized to `/\evil.com`, which many browsers interpret as a host separator, leading to an external redirect. This bypasses same-origin restrictions in OIDC, SAML, and OAuth flows. The issue is fixed in version 0.204.0 (and probod v0.194.1) by implementing `path.Clean` normalization and explicitly rejecting backslashes before validation.

Affected products

  • Probo probo < 0.204.0

Timeline

  • 2026-05-26: disclosed
  • 2026-06-30: advisory

References