THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-g7gw-m874-7rmf (low) — Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter

[GHSA] GHSA-g7gw-m874-7rmf (low) — Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter

medgithub_advisoriesPublished 2026-08-27

GHSA-g7gw-m874-7rmf Severity: low CVE: CVE-2026-42350

Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter

## Summary

The Kargo UI reads a `redirectTo` query parameter on the `/login` and `/token-renew` routes and, following a successful OIDC authentication, uses its value as the destination for client-side navigation. The parameter is treated as a path string but is not

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-g7gw-m874-7rmf