Cross-Origin Redirect Vulnerability in SecureDrop Client by Freedom of the Press Foundation
CVE-2026-49996
3.7LOW
What is CVE-2026-49996?
The SecureDrop Client, a tool designed for journalists to securely communicate with sources and manage submissions, has a vulnerability that allows a malicious SecureDrop Server to bypass the origin limitations of securedrop-proxy. This issue arises from the server's ability to respond to requests with cross-origin redirects, exposing communication channels to potential security threats. The vulnerability was addressed in version 1.3.1, emphasizing the importance of keeping software updated to ensure the integrity of secure communications.
Affected Version(s)
securedrop-client < 1.3.1
