CVE-2026-53989
Received Received - Intake

Open Redirect in Dockhand Before 1.0.36

Vulnerability report for CVE-2026-53989, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulnCheck

Description

Dockhand before 1.0.36 contains an open redirect vulnerability in the OIDC initiation endpoint that allows unauthenticated remote attackers to redirect authenticated users to attacker-controlled sites by injecting an unvalidated redirect query parameter. Attackers can craft a malicious link targeting the OIDC callback flow to capture authorization codes via the Referer header and conduct follow-up credential phishing against any Dockhand account after a legitimate login.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
finsys dockhand to 1.0.36 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-601 The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-53989 is an open redirect vulnerability in Dockhand versions before 1.0.36. It exists in the OIDC initiation endpoint where an unauthenticated remote attacker can inject an unvalidated redirect query parameter. This allows attackers to redirect authenticated users to attacker-controlled websites during the OIDC callback flow.

Detection Guidance

To detect this vulnerability, monitor network traffic for unexpected redirects from the OIDC initiation endpoint in Dockhand versions before 1.0.36. Check HTTP logs for unusual query parameters like 'redirect' or 'callback' with external URLs. Use tools like Wireshark or tcpdump to inspect traffic to the OIDC endpoint for unvalidated redirect attempts.

Impact Analysis

This vulnerability enables attackers to capture authorization codes via the Referer header and conduct credential phishing attacks against Dockhand accounts after a legitimate login. Users may unknowingly expose their credentials to malicious sites.

Mitigation Strategies

Immediately upgrade Dockhand to version 1.0.36 or later to patch the vulnerability. If upgrading is not possible, disable the OIDC initiation endpoint or implement strict input validation for redirect parameters. Monitor for suspicious login attempts or phishing activities targeting Dockhand accounts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-53989. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart