Open redirect: your domain as a phishing link

An open redirect forwards visitors to whatever address a parameter names. The link starts with your trusted domain; the page it ends on belongs to someone else.

Example

Vulnerable
app.get("/learn", (req, res) => {
  res.redirect(req.query.url);
});
Fixed
app.get("/learn", (req, res) => {
  const target = String(req.query.url ?? "/");
  // a single leading slash: same site only (not //evil.com, not /\evil.com)
  const local = /^\/(?![\/\\])/.test(target);
  res.redirect(local ? target : "/");
});

How it happens

Login flows and tracking links take a return URL — ?next=, ?url=, ?redirect= — and pass it straight to res.redirect or a Location header. Attackers send links like https://your-site.com/learn?url=https://your-site.login-check.com, which pass the visual check and land on a copy of your login page. Combined with OAuth flows, an open redirect can also leak authorisation codes.

How to fix it

Only redirect where you meant to.

  • Allow relative paths that start with exactly one /
  • Or compare the destination with an allowlist of hosts
  • Watch for //evil.com and /\evil.com, which browsers treat as other hosts
  • Store the return path server-side instead of in the URL when you can

How RepoVerse finds it

  • ModerateRequest input decides where the user is redirected

    A link on your own domain forwards victims to any site — the mechanic of a convincing phishing page.

    data flow · CWE-601

  • ModerateRedirect target taken from the request

    The caller chooses where this sends people, which is the whole mechanic of a convincing phishing link on your own domain.

    pattern · CWE-601

Questions

Is an open redirect a serious vulnerability?
It is usually rated moderate on its own, but it makes phishing far more convincing and can be chained with OAuth or SSRF weaknesses into something worse.
How does RepoVerse detect open redirects?
It traces request input to res.redirect, Location headers and framework redirect helpers, and does not report destinations that begin with a literal local path.

Related

Updated 2026-10-11