{"id":"CVE-2026-58491","published":"2026-09-21T19:17:06.910","lastModified":"2026-09-24T21:25:27.050","description":"Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.5, the /@warpgate/api/sso/providers/:name/start endpoint stores an attacker-controlled next parameter that the POST /@warpgate/api/sso/return handler inserts without HTML escaping into the response generated by warpgate-protocol-http/src/api/sso_provider_list.rs. A victim who follows a crafted link and completes SSO can cause markup and JavaScript to execute in the authenticated Warpgate origin, allowing access to session data and actions through user APIs, and through administrator APIs only when the victim is an administrator. The GET /@warpgate/api/sso/return path also uses the same unvalidated value as a redirect destination, enabling an open redirect. This issue is fixed in version 0.25.5.","cvssScore":9.3,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N","cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://github.com/warp-tech/warpgate/commit/eab0548f018d95b5f96f8e913527000e05ed93a2","tags":[]},{"url":"https://github.com/warp-tech/warpgate/releases/tag/v0.25.5","tags":[]},{"url":"https://github.com/warp-tech/warpgate/security/advisories/GHSA-3c3w-75j2-7h74","tags":[]}],"exploitRefs":[{"url":"https://github.com/warp-tech/warpgate/commit/eab0548f018d95b5f96f8e913527000e05ed93a2","tags":[]},{"url":"https://github.com/warp-tech/warpgate/releases/tag/v0.25.5","tags":[]},{"url":"https://github.com/warp-tech/warpgate/security/advisories/GHSA-3c3w-75j2-7h74","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows an attacker to inject malicious JavaScript into the response, potentially leading to session hijacking and unauthorized actions. It also enables open redirects, which can be used to redirect users to malicious sites.","exploitability":"Exploitation is relatively straightforward once a victim clicks a crafted link. Precondition is that the victim must complete SSO authentication.","blast_radius":"If exploited, the attacker can access session data and perform actions through user APIs, and potentially through administrator APIs if the victim is an admin.","remediation":"Upgrade to version 0.25.5 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","sso","redirect","web"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T09:04:19.811Z"}}