Open Redirect Vulnerability in Dockhand by Finsys
CVE-2026-53989
5.3MEDIUM
What is CVE-2026-53989?
Dockhand prior to version 1.0.36 is susceptible to an open redirect vulnerability found in the OIDC initiation endpoint. This flaw enables unauthenticated remote attackers to manipulate redirect query parameters, potentially redirecting authenticated users to harmful sites. By crafting a malicious link targeting the OIDC callback flow, attackers can capture sensitive authorization codes via the Referer header, which may facilitate follow-up credential phishing attacks against any affected Dockhand account after a legitimate user login.
Affected Version(s)
dockhand 0 < 1.0.36
