← Back to search

CVE-2026-58491

9.3 CRITICALpublic exploit available

Published 2026-09-21 · Updated 2026-09-24

AI risk analysis

Summary
The flaw allows an attacker to inject malicious JavaScript into the response, potentially leading to session hijacking and unauthorized actions. It also enables open redirects, which can be used to redirect users to malicious sites.
Exploitability
Exploitation is relatively straightforward once a victim clicks a crafted link. Precondition is that the victim must complete SSO authentication.
Blast radius
If exploited, the attacker can access session data and perform actions through user APIs, and potentially through administrator APIs if the victim is an admin.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to version 0.25.5 or later.
rcessoredirectweb

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.5, the /@warpgate/api/sso/providers/:name/start endpoint stores an attacker-controlled next parameter that the POST /@warpgate/api/sso/return handler inserts without HTML escaping into the response generated by warpgate-protocol-http/src/api/sso_provider_list.rs. A victim who follows a crafted link and completes SSO can cause markup and JavaScript to execute in the authenticated Warpgate origin, allowing access to session data and actions through user APIs, and through administrator APIs only when the victim is an administrator. The GET /@warpgate/api/sso/return path also uses the same unvalidated value as a redirect destination, enabling an open redirect. This issue is fixed in version 0.25.5.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Weaknesses

CWE-79

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.