Open Redirect Vulnerability in DevPush by Hunvreus
CVE-2026-30346

4.3MEDIUM

Key Information:

Vendor

Hunvreus

Status
Vendor
CVE Published:
27 April 2026

What is CVE-2026-30346?

An open redirect vulnerability exists in the /api/google/authorize endpoint of Hunvreus DevPush v0.3.2, which allows attackers to craft a URL that redirects users to malicious websites. This flaw can be exploited by unauthorized entities to manipulate the redirection process, potentially leading users into phishing schemes or other harmful outcomes. Ensuring secure URL validation is critical to mitigate this issue and protect users from malicious redirects.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.