Cross-Origin Redirect Vulnerability in SecureDrop Client by Freedom of the Press Foundation
CVE-2026-49996

3.7LOW

Key Information:

Vendor
CVE Published:
20 August 2026

What is CVE-2026-49996?

The SecureDrop Client, a tool designed for journalists to securely communicate with sources and manage submissions, has a vulnerability that allows a malicious SecureDrop Server to bypass the origin limitations of securedrop-proxy. This issue arises from the server's ability to respond to requests with cross-origin redirects, exposing communication channels to potential security threats. The vulnerability was addressed in version 1.3.1, emphasizing the importance of keeping software updated to ensure the integrity of secure communications.

Affected Version(s)

securedrop-client < 1.3.1

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.