OpenRun is an open-source, self-hosted GitOps platform for deploying web apps and internal tools to Docker or Kubernetes. Prior to version 0.17.7, the restrictions on redirect URLs in openrun can be bypassed by attackers, leading to open redirect attacks. This issue has been patched in version 0.17.7.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-h5g6-xmh4-hc37 | OpenRun: Redirect URL validation bypass using //host paths leads to Open Redirect |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 01 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenRun is an open-source, self-hosted GitOps platform for deploying web apps and internal tools to Docker or Kubernetes. Prior to version 0.17.7, the restrictions on redirect URLs in openrun can be bypassed by attackers, leading to open redirect attacks. This issue has been patched in version 0.17.7. | |
| Title | OpenRun: Redirect URL validation bypass using //host paths leads to Open Redirect | |
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-01T19:52:31.031Z
Reserved: 2026-06-16T16:44:00.625Z
Link: CVE-2026-55252
No data.
Status : Received
Published: 2026-10-01T20:17:26.110
Modified: 2026-10-01T20:17:26.110
Link: CVE-2026-55252
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA