Open Redirect in Basecamp's Google Sign-In for Rails Applications
CVE-2025-58067
What is CVE-2025-58067?
A vulnerability exists in Basecamp's Google Sign-In gem for Rails applications, allowing potential redirection to a malicious site. This issue arises when a session store's 'proceed_to' value is improperly set to a protocol-relative URL. Malicious actors could exploit this by manipulating session values through a deceptive form submission, which may lead to unauthorized redirection if combined with other attacks targeting OAuth2 request parameters. The vulnerability has been addressed in version 1.3.1, and there are currently no workarounds.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
google_sign_in < 1.3.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
