Executive brief
Concourse CI, an open-source continuous integration tool, is vulnerable to an open redirect issue during its login process. An attacker can trick users into clicking a specially crafted link that, after a successful login, redirects them to a malicious external website. This technique is commonly used in phishing campaigns to deceive users into providing credentials to a fraudulent site that mimics the legitimate service.
Technical details
An open redirect vulnerability exists in Concourse CI's login flow due to improper handling of the 'redirect_uri' parameter. The root cause is related to how Go's 'url' package processes encoded characters; specifically, double-encoding or including backslashes can bypass path validation logic, causing a relative path like '/%2Fexample.com' to be interpreted as an absolute URL '//example.com'. An unauthenticated attacker can craft a URL that redirects a user to an arbitrary external site after they complete the login process. This issue is fixed in Concourse version 8.2.3.
Affected products
- Concourse Concourse CI < 8.2.3
Timeline
- 2026-05-27: disclosed
- 2026-07-01: advisory: GitHub Advisory published
- 2026-07-01: patched: Fix confirmed in version 8.2.3