Open Redirect Vulnerability in Probo GRC Platform
CVE-2026-49820

4.7MEDIUM

Key Information:

Vendor

Getprobo

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-49820?

Probo, a self-hostable governance, risk, and compliance (GRC) platform, has a vulnerability in its saferedirect package that affects the validation of redirect URLs used in authentication processes. Prior to version 0.19.3.1, the validator's implementation only checked the second character of relative paths, allowing certain malicious URLs to bypass validation. As a result, attackers could exploit this flaw to redirect users to unwanted external domains, facilitating open-redirect phishing attacks. This vulnerability has been addressed in version 0.19.4.1 by implementing strict path normalization and rejection of backslashes in URLs. Users are encouraged to upgrade to the latest version to mitigate the risk.

Affected Version(s)

probo < 0.193.1

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.