Open Redirect Vulnerability in DevPush by Hunvreus
CVE-2026-30346
4.3MEDIUM
What is CVE-2026-30346?
An open redirect vulnerability exists in the /api/google/authorize endpoint of Hunvreus DevPush v0.3.2, which allows attackers to craft a URL that redirects users to malicious websites. This flaw can be exploited by unauthorized entities to manipulate the redirection process, potentially leading users into phishing schemes or other harmful outcomes. Ensuring secure URL validation is critical to mitigate this issue and protect users from malicious redirects.
