CVE-2026-55252
Received Received - Intake

Open Redirect Bypass in OpenRun Platform

Vulnerability report for CVE-2026-55252, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: GitHub, Inc.

Description

OpenRun is an open-source, self-hosted GitOps platform for deploying web apps and internal tools to Docker or Kubernetes. Prior to version 0.17.7, the restrictions on redirect URLs in openrun can be bypassed by attackers, leading to open redirect attacks. This issue has been patched in version 0.17.7.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openrundev openrun to 0.17.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-601 The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-55252 is an open redirect bypass vulnerability in OpenRun, a self-hosted GitOps platform. Attackers exploit it by crafting URLs with double slashes (e.g., http://127.0.0.1:25222//fushuling.com) to bypass redirect URL restrictions. Browsers interpret // as protocol-relative, redirecting to external sites like http://fushuling.com.

Detection Guidance

To detect this vulnerability, check if your openrun instance is running a version prior to 0.17.7. Use commands like 'curl -s https://your-openrun-instance.com/version' or inspect the application logs for version details. Look for redirect attempts using URLs starting with // to bypass restrictions.

Impact Analysis

This vulnerability allows attackers to trick users into visiting malicious sites via OpenRun's redirect functionality. It could lead to phishing attacks, credential theft, or malware distribution if users are deceived by legitimate-looking URLs.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it is an open redirect issue in a self-hosted GitOps platform. However, if exploited, it could potentially lead to phishing attacks or unauthorized data access, which may indirectly impact compliance by exposing sensitive data or violating access controls.

Mitigation Strategies

Upgrade openrun to version 0.17.7 or later immediately. This version includes a patch that rejects redirect targets starting with //. Verify the fix by testing redirect functionality with malicious URLs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55252. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart