Open Redirect Vulnerability in Onlook Web Application
CVE-2025-63784
6.5MEDIUM
What is CVE-2025-63784?
An Open Redirect vulnerability exists in the OAuth callback handler of the Onlook web application version 0.2.32. This flaw allows the application to trust the X-Forwarded-Host header value without proper validation, enabling a remote attacker to manipulate this header. By doing so, the attacker can craft a redirect URL that can send authenticated users to an arbitrary external site controlled by the attacker, thereby increasing the risk of phishing attacks.
