CVE-2026-85676
Dub Open Redirect via Unrestricted redir_url Parameter
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
Dub contains an open redirect vulnerability in the redir_url query parameter that is accepted on every short link without validation or domain allowlist enforcement. Attackers can append the redir_url parameter to any short link to redirect visitors to arbitrary external URLs through the trusted Dub domain, bypassing destination blacklists and potentially enabling phishing attacks with link cloaking enabled.
| CWE | CWE-601 |
| Vendor | dubinc |
| Product | dub |
| Published | Sep 4, 2026 |
| Last Updated | Sep 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for dubinc dub
Be the first to know when new medium vulnerabilities affecting dubinc dub are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
Affected Versions
dubinc / dub
0 โค 73415cf5e6be13ce9adb7ba5e97474307db34a17
References
github.com: https://github.com/dubinc/dub/issues/4337 github.com: https://github.com/dubinc/dub github.com: https://github.com/dubinc/dub/blob/73415cf5e6be13ce9adb7ba5e97474307db34a17/apps/web/lib/middleware/utils/get-final-url.ts vulncheck.com: https://www.vulncheck.com/advisories/dub-open-redirect-via-unrestricted-redir-url-parameter
Credits
George Chen