Open Redirect Vulnerability in Dub by Dub Inc.
CVE-2026-85676
5.3MEDIUM
What is CVE-2026-85676?
The Dub application presents an open redirect issue stemming from the unvalidated redir_url query parameter. This vulnerability permits attackers to exploit short links created by Dub, allowing them to redirect users to malicious external URLs. By appending the redir_url parameter to any short link, unauthorized redirections can occur, effectively circumventing destination blacklists. This flaw poses a significant risk as it enables potential phishing attacks through URL cloaking, compromising user security and trust.
Affected Version(s)
dub 0 <= 73415cf5e6be13ce9adb7ba5e97474307db34a17
