๐Ÿ” CVE Alert

CVE-2026-49820

MEDIUM 4.7

Probo has an open redirect bypass via path normalization

CVSS Score
4.7
EPSS Score
0.0%
EPSS Percentile
0th

Probo is a self-hostable governance, risk, and compliance (GRC) platform built for engineering and security teams. Probo's `saferedirect` package validates redirect URLs used across authentication flows (OIDC, SAML, session transfer, OAuth connectors, and trust-center magic links). Prior to version 0.19.3.1, the validator only inspected the second character of relative paths, so a URL like `/../\evil.com` passed validation because the second character is `.`. Go's `http.Redirect` normalizes this path to `/\evil.com` before setting the `Location` header. Browsers can interpret the backslash as a host separator and redirect the user to an external domain (`https://evil.com`), bypassing the intended same-origin restriction. This enables open-redirect phishing: an attacker can craft a `continue` parameter (or embed a malicious URL in a session-transfer token) that appears to originate from a trusted Probo domain but redirects victims elsewhere. This is fixed in `go.probo.inc/probo` 0.193.1 by normalizing relative paths with `path.Clean` before validation, rejecting backslashes (including percent-encoded `%5c`) anywhere in the path, and re-checking the normalized result for protocol-relative and backslash prefixes. Self-hosted deployments should upgrade to probod v0.194.1 or later. SaaS deployments on getprobo.com are patched. No practical workaround is available for self-hosted installations.

CWE CWE-601
Vendor getprobo
Product probo
Published Aug 13, 2026
Stay Ahead of the Next One

Get instant alerts for getprobo probo

Be the first to know when new medium vulnerabilities affecting getprobo probo are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

getprobo / probo
< 0.193.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/getprobo/probo/security/advisories/GHSA-x7qq-m748-8p2c github.com: https://github.com/getprobo/probo/blob/main/SECURITY_NOTES.md