GHSA-mj24-pqx2-6788

Suggest an improvement
Source
https://github.com/advisories/GHSA-mj24-pqx2-6788
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-mj24-pqx2-6788/GHSA-mj24-pqx2-6788.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mj24-pqx2-6788
Aliases
Published
2026-04-03T12:31:10Z
Modified
2026-06-25T23:11:42Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N CVSS Calculator
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Casdoor vulnerable to Open Redirect
Details

A vulnerability was identified in Casdoor 2.356.0. Affected by this issue is some unknown functionality of the component OAuth Authorization Request Handler. Such manipulation of the argument redirect_uri leads to open redirect. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Database specific
{
    "cwe_ids":  [
        "CWE-601"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-04-10T15:36:26Z",
    "nvd_published_at":  "2026-04-03T12:16:19Z",
    "severity":  "LOW"
}
References

Affected packages

Go / github.com/casdoor/casdoor

Package

Name
github.com/casdoor/casdoor
View open source insights on deps.dev
Purl
pkg:golang/github.com/casdoor/casdoor

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.1000.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-mj24-pqx2-6788/GHSA-mj24-pqx2-6788.json"