Open Redirect Vulnerability in Probo GRC Platform
CVE-2026-49820
4.7MEDIUM
What is CVE-2026-49820?
Probo, a self-hostable governance, risk, and compliance (GRC) platform, has a vulnerability in its saferedirect package that affects the validation of redirect URLs used in authentication processes. Prior to version 0.19.3.1, the validator's implementation only checked the second character of relative paths, allowing certain malicious URLs to bypass validation. As a result, attackers could exploit this flaw to redirect users to unwanted external domains, facilitating open-redirect phishing attacks. This vulnerability has been addressed in version 0.19.4.1 by implementing strict path normalization and rejection of backslashes in URLs. Users are encouraged to upgrade to the latest version to mitigate the risk.
Affected Version(s)
probo < 0.193.1
