Open Redirect Vulnerability in Dockhand by Finsys
CVE-2026-53989

5.3MEDIUM

Key Information:

Vendor

Finsys

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-53989?

Dockhand prior to version 1.0.36 is susceptible to an open redirect vulnerability found in the OIDC initiation endpoint. This flaw enables unauthenticated remote attackers to manipulate redirect query parameters, potentially redirecting authenticated users to harmful sites. By crafting a malicious link targeting the OIDC callback flow, attackers can capture sensitive authorization codes via the Referer header, which may facilitate follow-up credential phishing attacks against any affected Dockhand account after a legitimate user login.

Affected Version(s)

dockhand 0 < 1.0.36

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Katriel Moses
VulnCheck
.