Skip to content

Reject protocol-relative URLs in post-login redirect - #190

Closed
B58TU wants to merge 1 commit into
crackmesone:mainfrom
B58TU:fix/login-open-redirect
Closed

B58TU wants to merge 1 commit into
crackmesone:mainfrom
B58TU:fix/login-open-redirect

Conversation

@B58TU

@B58TU B58TU commented Sep 23, 2026 •

Copy link
Copy Markdown

What

The post-login redirect guard only checked startswith('/'). A same-site Referer like https://crackmes.one//evil.com survives the netloc check in login_get/register_get (its path is //evil.com), and Werkzeug emits Location: //evil.com verbatim — which browsers resolve as https://evil.com/. So right after a successful login on the real domain, a victim can be bounced to an attacker-controlled host (CWE-601). The backslash twin /\evil.com behaves the same way under WHATWG URL parsing for special schemes.

Fix

One guard at the single place session['login_redirect'] is released (login_post): reject values that don't start with /, start with //, or contain a backslash. Covers both writers (login_get and the duplicated logic in register_get) without touching them.

Test

  • New test_login_does_not_redirect_to_protocol_relative_referrer (parametrized over // and \ Referers) — fails on main, passes with the fix.
  • Existing referrer tests (test_login_by_email_and_safe_referrer, test_login_does_not_redirect_to_external_referrer) still pass; full tests/test_controller_edge_cases.py + tests/test_routes.py: 44 passed.

Same sink class as CVE-2025-62595 (Koa redirect()).

@B58TU B58TU closed this Sep 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant