Impact
Prior to version 0.17.7, OpenRun does not properly validate redirect URLs when the path contains an escaped host reference such as //host. An attacker can supply a crafted link that bypasses this check, resulting in an open redirect that sends users to arbitrary external sites. The primary impact is the ability to redirect users to malicious domains, facilitating phishing, credential harvesting, or social‑engineering attacks. The vulnerability does not grant direct execution or access to sensitive data but can severely undermine user trust and security posture.
Affected Systems
The affected product is OpenRun, developed by openrundev. Any installation using a version older than 0.17.7 is vulnerable. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. EPSS data is not available, so the likelihood of widespread exploitation remains unclear; it is not listed in the CISA KEV catalog, suggesting no known mass exploitation. Nevertheless, the open redirect can be triggered simply by visiting a crafted URL, so the attack vector is remote and does not require privileged access. The vulnerability is directly exploitable through standard HTTP requests to an OpenRun instance using the vulnerable redirect endpoint.
OpenCVE Enrichment
Github GHSA