Impact
Warpgate, an open‑source SSH/HTTPS/MySQL bastion host, contains a markup injection flaw in its form_post SSO return page. The vulnerable code serializes redirect parameters and IdP error messages into JavaScript without neutralizing script‑closing characters, allowing an attacker to inject arbitrary markup into the page. The result is content spoofing – a false login form or meta refresh – because the configured Content‑Security‑Policy blocks actual JavaScript execution. The flaw does not provide code execution or data exfiltration, and has a low CVSS score of 2.4.
Affected Systems
The issue affects warp-tech WarpGate deployments running any version earlier than v0.27.6. Users running v0.27.6 or newer are not impacted.
Risk and Exploitability
The CVSS score of 2.4 suggests low severity, and the EPSS score is not available, indicating no known high exploitation probability. Though the vulnerability is listed in no KEV catalog, it requires an attacker to influence an identity provider’s redirect URL or attacker‑controlled user claims, and the victim must complete the form_post SSO flow for the injected markup to render. These constraints make exploitation difficult and context‑specific. Nonetheless, the lack of active mitigation and potential for social engineering or compromised IdPs introduce a moderate risk for environments that rely heavily on SSO.
OpenCVE Enrichment