Executive brief
OpenStatus, an open-source monitoring platform, contains a security vulnerability in its onboarding process. By tricking an authenticated user into clicking a specially crafted link, an attacker can execute malicious code within the user's browser session. This could allow the attacker to steal login credentials, perform unauthorized actions on the user's behalf, or gain a foothold to attack internal systems.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the onboarding endpoint of OpenStatus (apps/dashboard/src/app/(dashboard)/onboarding/client.tsx). The application improperly handles the 'callbackUrl' query parameter, passing it directly to Next.js 'router.push' without sufficient validation. Because 'router.push' eventually interacts with 'window.location', an attacker can provide a 'javascript:' URI to trigger script execution. Successful exploitation requires a victim to click a malicious link while authenticated. This can lead to full session compromise, unauthorized API requests, and data exfiltration. The issue was addressed in commit 43d9b2b9ef8ae1a98f9bdc8a9f86d6a3dfaa2dfb by implementing origin and protocol checks on the redirect URL.
Affected products
- openstatusHQ openstatus up to 1b678e71a85961ae319cbb214a8eae634059330c
Timeline
- 2026-03-14: disclosed: Vulnerability discovered and reported to maintainers.
- 2026-03-13: patched: Fix merged via pull request 1981 (Note: PR date precedes report date in source, likely due to timezone or rapid response).
- 2026-04-08: advisory: CVE-2026-5808 published.
References
- https://gist.github.com/TrebledJ/ab83abb1ca7ff6c1f39e16a37020f323
- https://github.com/openstatusHQ/openstatus/
- https://github.com/openstatusHQ/openstatus/commit/43d9b2b9ef8ae1a98f9bdc8a9f86d6a3dfaa2dfb
- https://github.com/openstatusHQ/openstatus/pull/1981
- https://vuldb.com/submit/787321
- https://vuldb.com/vuln/356245
- https://vuldb.com/vuln/356245/cti