Skip to main content

URL Redirection to Untrusted Site ('Open Redirect')

CVE-2025-67713

Severity Medium
Score 5.3/10

Summary

Miniflux 2 is an open source feed reader. Versions through 2.2.14 treat "redirect_url" as safe when "url.Parse(...).IsAbs()" is false, enabling phishing flows after login. Protocol-relative URLs like //ikotaslabs.com have an empty scheme and pass that check, allowing post-login redirects to attacker-controlled sites. This issue is fixed in version 2.2.15.

  • LOW
  • NETWORK
  • LOW
  • CHANGED
  • REQUIRED
  • NONE
  • LOW
  • NONE

CWE-601 - Open Redirect

An open redirect attack employs a URL parameter, HTML refresh tags, or a DOM based location change to exploit the trust of a vulnerable domain to direct the users to a malicious website. The attack could lead to higher severity vulnerabilities such as unauthorized access control, account takeover, XSS, and more.

Advisory Timeline

  • Published