Description
OpenRun is an open-source, self-hosted GitOps platform for deploying web apps and internal tools to Docker or Kubernetes. Prior to version 0.17.7, the restrictions on redirect URLs in openrun can be bypassed by attackers, leading to open redirect attacks. This issue has been patched in version 0.17.7.
Published: 2026-10-01
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Open Redirect
Action: Immediate Patch
AI Analysis

Impact

Prior to version 0.17.7, OpenRun does not properly validate redirect URLs when the path contains an escaped host reference such as //host. An attacker can supply a crafted link that bypasses this check, resulting in an open redirect that sends users to arbitrary external sites. The primary impact is the ability to redirect users to malicious domains, facilitating phishing, credential harvesting, or social‑engineering attacks. The vulnerability does not grant direct execution or access to sensitive data but can severely undermine user trust and security posture.

Affected Systems

The affected product is OpenRun, developed by openrundev. Any installation using a version older than 0.17.7 is vulnerable. No other vendors or products are listed as affected.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity. EPSS data is not available, so the likelihood of widespread exploitation remains unclear; it is not listed in the CISA KEV catalog, suggesting no known mass exploitation. Nevertheless, the open redirect can be triggered simply by visiting a crafted URL, so the attack vector is remote and does not require privileged access. The vulnerability is directly exploitable through standard HTTP requests to an OpenRun instance using the vulnerable redirect endpoint.

Generated by OpenCVE AI on October 1, 2026 at 21:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the OpenRun installation to version 0.17.7 or later, which restores proper redirect URL validation.
  • After upgrading, confirm that the redirect endpoint no longer accepts paths beginning with //host by attempting to access a test URL such as http://your-openrun-instance/redirect?url=%2F%2Fmalicious.example.com
  • Review any custom redirect handling or reverse‑proxy configurations to ensure they do not re‑enable the bypassed validation logic

Generated by OpenCVE AI on October 1, 2026 at 21:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-h5g6-xmh4-hc37 OpenRun: Redirect URL validation bypass using  //host  paths leads to Open Redirect
History

Thu, 01 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
Description OpenRun is an open-source, self-hosted GitOps platform for deploying web apps and internal tools to Docker or Kubernetes. Prior to version 0.17.7, the restrictions on redirect URLs in openrun can be bypassed by attackers, leading to open redirect attacks. This issue has been patched in version 0.17.7.
Title OpenRun: Redirect URL validation bypass using //host paths leads to Open Redirect
Weaknesses CWE-601
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-01T19:52:31.031Z

Reserved: 2026-06-16T16:44:00.625Z

Link: CVE-2026-55252

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T20:17:26.110

Modified: 2026-10-01T20:17:26.110

Link: CVE-2026-55252

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T22:00:17Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')