Open Redirect Vulnerability in Dub by Dub Inc.
CVE-2026-85676

5.3MEDIUM

Key Information:

Vendor

Dubinc

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-85676?

The Dub application presents an open redirect issue stemming from the unvalidated redir_url query parameter. This vulnerability permits attackers to exploit short links created by Dub, allowing them to redirect users to malicious external URLs. By appending the redir_url parameter to any short link, unauthorized redirections can occur, effectively circumventing destination blacklists. This flaw poses a significant risk as it enables potential phishing attacks through URL cloaking, compromising user security and trust.

Affected Version(s)

dub 0 <= 73415cf5e6be13ce9adb7ba5e97474307db34a17

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.