Impact
Dub includes an open redirect flaw that accepts an unrestricted redir_url query parameter on every shortened link. Because the parameter is not validated or restricted to a whitelisted domain, attackers can append redir_url to any Dub short URL and cause visitors to be automatically sent to an arbitrary external site. This bypasses the built‑in destination blacklist and, when link cloaking is enabled, allows attackers to create convincingly disguised phishing links that exploit the trust people place in the Dub domain.
Affected Systems
All deployments of Dub by dubinc. The vulnerability applies to every short link generated by the system, regardless of version, as the redir_url parameter is currently not guarded by any validation logic.
Risk and Exploitability
The CVSS score of 5.3 classifies the flaw as medium severity. The EPSS value is currently unavailable, so the probability of exploitation in the wild is uncertain, but the flaw's simplicity and the ability to craft malicious short URLs make it likely to be used for phishing campaigns. The vulnerability is not listed in the CISA KEV catalog, yet the risk of accidental spread remains high because the short links are publicly distributed.
OpenCVE Enrichment