OSV 1.4.0 · github-reviewed · 修改于 2026-07-21 21:36
发布时间
2026-06-24 00:42
GitHub 审查时间
2026-06-24 00:42
NVD 发布时间
2026-06-25 05:16
源文件
advisories/github-reviewed/2026/06/GHSA-xxhq-69mf-w8cr/GHSA-xxhq-69mf-w8cr.json
An open redirect vulnerability exists in Gogs where attacker-controlled redirect_to parameters can bypass validation, allowing redirection to arbitrary external sites.
All redirects in Gogs that are validated via the IsSameSite function are vulnerable:
func IsSameSite(url string) bool {
return len(url) >= 2 && url[0] == '/' && url[1] != '/' && url[1] != '\\'
}
The function only inspects the first two characters of the URL string. This check fails to account for directory traversal sequences followed by backslashes. For example:
/a/../\example.com
The IsSameSite function checks the input supplied to the redirect_to query parameter value /a/../\example.com and considers it valid.
Because web browsers normalize backslashes \ to forward slashes /, the normalized URL becomes //example.com.
The normalized URL becomes:
//example.com
Resulting in a cross-origin redirect.
This affects all endpoints using the redirect_to query parameter, including login and other post-action flows.
redirect_to query parameter that redirects a user to a site the attacker wants them to visit:http://192.168.236.132:3000/user/login?redirect_to=/a/../\example.com
<img width="1339" height="536" alt="image" src="https://github.com/user-attachments/assets/3c2a13b8-f0b7-42c2-a223-6f0ebf083589" />
<br>
<br>