Open Redirect Vulnerability in Waku by Waku.js
CVE-2026-49456
3.1LOW
What is CVE-2026-49456?
The Waku minimal React framework has a vulnerability in the unstable_redirect() helper, which allows reflected user-controlled input to be used in HTTP Location response headers without proper validation. This flaw can be exploited to conduct open redirect attacks, redirecting users to malicious external domains. This can facilitate phishing efforts, credential theft, and unauthorized access to sensitive information. Attackers can leverage scheme-relative URLs to bypass common whitelist filters, enhancing the risk of exploitation. The issue has been rectified in version 1.0.0-beta.1.
Affected Version(s)
waku < 1.0.0-beta.1
