Executive brief
Dub is a link attribution and shortening platform used by marketing teams to track and manage shortened URLs. The platform contains an open redirect vulnerability in the redir_url query parameter that allows attackers to redirect users to arbitrary external websites by appending the parameter to any short link, potentially enabling phishing attacks with the appearance of coming from the trusted Dub domain.
Technical details
The vulnerability is an open redirect in the redir_url query parameter that is accepted on every short link without validation or domain allowlist enforcement. Attackers can craft malicious short links by appending the redir_url parameter with an arbitrary external URL to bypass destination blacklists and enable phishing attacks, especially when link cloaking is enabled. The vulnerable code path accepts this parameter on all redirects without proper URL validation. This is a network-accessible vulnerability requiring no authentication or user interaction beyond clicking the malicious short link. The attack leverages the trust users place in the legitimate Dub domain to deliver phishing payloads.
Affected products
- Dub Dub <UNKNOWN>
Timeline
- 2026-09-04: disclosed