Impact
The SecureDrop client includes a proxy that limits outbound requests to a defined origin. The vulnerability, a failure to validate redirects (CWE‑601), allows a malicious SecureDrop server to supply an HTTP 302 response that redirects the client to an arbitrary host. By exploiting this flaw the attacker can bypass the proxy’s origin restriction and cause the client to connect to unintended services, potentially leading to disclosure of confidential data or modification of communications.
Affected Systems
Freedom of Press SecureDrop Client. All releases prior to version 1.3.1 are affected. The issue is fixed in version 1.3.1.
Risk and Exploitability
The CVSS score of 3.7 classifies the overall risk as low, and the EPSS score is unavailable. The vulnerability is not listed in the CISA KEV catalog. Exploitability requires an attacker to control the SecureDrop server that a journalist’s workstation uses; once that control is established, the attacker can issue a cross‑origin redirect that bypasses the proxy’s origin check. Because the SecureDrop server is a dedicated physical machine exposed only via Tor, the likelihood of a compromised server is moderate. The lack of publicly available exploits and limited attack surface mean the threat window is narrow, but the potential impact to the client remains significant if the server is compromised.
OpenCVE Enrichment