Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
The post-login redirect guard only checked
startswith('/'). A same-site Referer likehttps://crackmes.one//evil.comsurvives the netloc check inlogin_get/register_get(its path is//evil.com), and Werkzeug emitsLocation: //evil.comverbatim — which browsers resolve ashttps://evil.com/. So right after a successful login on the real domain, a victim can be bounced to an attacker-controlled host (CWE-601). The backslash twin/\evil.combehaves the same way under WHATWG URL parsing for special schemes.Fix
One guard at the single place
session['login_redirect']is released (login_post): reject values that don't start with/, start with//, or contain a backslash. Covers both writers (login_getand the duplicated logic inregister_get) without touching them.Test
test_login_does_not_redirect_to_protocol_relative_referrer(parametrized over//and\Referers) — fails on main, passes with the fix.test_login_by_email_and_safe_referrer,test_login_does_not_redirect_to_external_referrer) still pass; fulltests/test_controller_edge_cases.py+tests/test_routes.py: 44 passed.Same sink class as CVE-2025-62595 (Koa
redirect()).