Route parameters are inserted into generated URLs without URI encoding.
When an application passes untrusted input to a route whose first path segment is dynamic, a value beginning with / can produce a scheme-relative URL. For example:
router.get('/:page', handler).as('pages.show')
response.redirect().toRoute('pages.show', {
page: '/evil.example.com',
})
This generates the following redirect:
Location: //evil.example.com
Browsers interpret this value as an external URL and redirect the user to https://evil.example.com.
The shared createURL() helper is used by route URL builders, including Router.makeUrl() and Response.redirect().toRoute().
Route parameter values were appended without encoding:
if (isDefined) {
uriSegments.push(`${value}${token.end}`)
}
Wildcard parameters had the same behavior:
uriSegments.push(`${values.join('/')}${token.end}`)
The issue does not affect APIs that intentionally accept complete redirect URLs. Exploitation requires an application to pass attacker-controlled data as a route parameter and use the generated URL as a redirect destination.
An attacker may craft a link on a trusted application domain that redirects a victim to an attacker-controlled website.
This can facilitate phishing and may be chained with authentication or OAuth flows that rely on trusted redirect destinations.
Applications are affected when they:
Route parameter values are now encoded using encodeURIComponent.
Wildcard values are encoded individually before being joined with /, preserving their intended segment separators:
if (isDefined) {
uriSegments.push(`${encodeURIComponent(String(value))}${token.end}`)
}
uriSegments.push(
`${values.map((value) => encodeURIComponent(String(value))).join('/')}${token.end}`
)
With the fix, /evil.example.com becomes:
/%2Fevil.example.com
Fixes targeting v6 and v7 have been published below.
{
"cwe_ids": [
"CWE-601"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-08T22:09:06Z",
"nvd_published_at": null,
"severity": "MODERATE"
}