Open redirect: your domain as a phishing link
An open redirect forwards visitors to whatever address a parameter names. The link starts with your trusted domain; the page it ends on belongs to someone else.
Example
app.get("/learn", (req, res) => {
res.redirect(req.query.url);
});app.get("/learn", (req, res) => {
const target = String(req.query.url ?? "/");
// a single leading slash: same site only (not //evil.com, not /\evil.com)
const local = /^\/(?![\/\\])/.test(target);
res.redirect(local ? target : "/");
});How it happens
Login flows and tracking links take a return URL — ?next=, ?url=, ?redirect= — and pass it straight to res.redirect or a Location header. Attackers send links like https://your-site.com/learn?url=https://your-site.login-check.com, which pass the visual check and land on a copy of your login page. Combined with OAuth flows, an open redirect can also leak authorisation codes.
How to fix it
Only redirect where you meant to.
- Allow relative paths that start with exactly one /
- Or compare the destination with an allowlist of hosts
- Watch for //evil.com and /\evil.com, which browsers treat as other hosts
- Store the return path server-side instead of in the URL when you can
How RepoVerse finds it
- ModerateRequest input decides where the user is redirected
A link on your own domain forwards victims to any site — the mechanic of a convincing phishing page.
data flow · CWE-601
- ModerateRedirect target taken from the request
The caller chooses where this sends people, which is the whole mechanic of a convincing phishing link on your own domain.
pattern · CWE-601
Questions
- Is an open redirect a serious vulnerability?
- It is usually rated moderate on its own, but it makes phishing far more convincing and can be chained with OAuth or SSRF weaknesses into something worse.
- How does RepoVerse detect open redirects?
- It traces request input to res.redirect, Location headers and framework redirect helpers, and does not report destinations that begin with a literal local path.
Related
- SSRF: when a request decides where your server connectsHow SSRF (CWE-918) lets a request choose where your server connects — internal services, cloud metadata at 169.254.169.254 — and how to build URLs safely.
- Cross-site scripting (XSS): how it works and how to stop itReflected, stored and DOM-based XSS (CWE-79) explained with vulnerable and fixed code, plus the template, CSP and cookie settings that limit the damage.
- GitHub security scanner for code, secrets and dependenciesScan a GitHub repository for injection flaws, leaked secrets and vulnerable dependencies. Data-flow traces from request to sink, lockfile-aware, with fixes.
Updated 2026-10-11