Open Redirect Vulnerability in YunaiV's OAuth2 Client
CVE-2026-97325
5.3MEDIUM
What is CVE-2026-97325?
A security flaw has been identified in YunaiV's ruoyi-vue-pro, specifically in the OAuth2 Client component. The issue lies within the function validOAuthClientFromCache, where improper handling of the redirect_uri parameter allows for open redirect vulnerabilities. This weakness can be exploited remotely, potentially leading to unauthorized access or redirection to malicious sites. The exploit code has been publicly released, heightening the urgency for administrators to address this vulnerability. Despite efforts to notify the vendor, no response has been received regarding the disclosure.
Affected Version(s)
ruoyi-vue-pro 2026.08
ruoyi-vue-pro 2026.08
