SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the Se
A vulnerability was determined in lcg0124 BootDo up to 5ccd963c74058036b466e038cff37de4056c1600. Affected by this vulner
A flaw was found in Moodle. An open redirect vulnerability in the OAuth login flow allows a remote attacker to redirect
A flaw has been found in Edimax BR-6258n up to 1.18. This issue affects the function formStaDrvSetup of the file /goform
A flaw has been found in busy up to 2.5.5. The affected element is an unknown function of the file source-code/busy-mast
action/cookie.php in ecrire in SPIP before 4.4.15 is prone to an open redirect vulnerability.
Capgo before 12.128.2 contains an open redirect vulnerability in stripe_portal and stripe_checkout endpoints that accept
draw.io is a configurable diagramming and whiteboarding application. Prior to version 29.7.9, the draw.io client accepts
Nextcloud is an open source content collaboration platform. From version 6.1.0 to before version 8.2.2, an attacker can
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1
In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible
A weakness has been identified in JeecgBoot up to 3.9.2. Impacted is the function HttpServletResponse.sendRedirect of th
Apprise is an open source library which allows you to send a notification to almost all of the most popular notification
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Ident
An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] vulnerability in Fortinet FortiNAC-F 7.6.
The Angular SSR is a server-rise rendering tool for Angular applications. An Open Redirect vulnerability exists in the i
Chamilo LMS is a learning management system. From 1.11.0 to 2.0-beta.1, anyone can trigger a malicious redirect through
ChurchCRM is an open-source church management system. Prior to 7.0.0, it was possible in many places across the ChurchCR
next-intl provides internationalization for Next.js. Applications using the `next-intl` middleware prior to version 4.9.
Masa CMS is affected by an Open Redirect vulnerability due to improper handling of scheme-relative URLs. The application
Saltcorn is an extensible, open source, no-code database application builder. Prior to versions 1.4.6, 1.5.6, and 1.6.0-
Open redirection vulnerability in the latest demo version of the Cradle eCommerce platform. The vulnerability occurs in
Kargo manages and automates the promotion of software artifacts. Prior to versions 1.7.10, 1.8.13, 1.9.8, and 1.10.2, Ka
Horilla is an HR and CRM software. In 1.5.0, the notification endpoints trust the unvalidated next parameter and redirec
The RedirectHandler middleware in microsoft/kiota-java (com.microsoft.kiota:microsoft-kiota-http-okHttp v1.9.0) and othe
The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. From 1.1.0 to 1.7.4
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Redirect module doe
Applications that use GeneralUtility::sanitizeLocalUrl to allow only local URLs are vulnerable to open redirect attacks
Open redirection vulnerability due to insufficient validation of the X-Forwarded-Host HTTP header. An attacker could cre
Open redirection vulnerability in the authentication system allows an attacker to use manipulated values in the X-Forwar
An unvalidated redirect was contained in Venueless' social login functionality and could be exploited for phishing using
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the client-side hashRedirect plugin calle
Open redirect vulnerability (CWE-601) in the _safe_redirect function of the click-tracking endpoint (/c/<token>/) in Mai
An unauthenticated URL redirection vulnerability has been identified in Archer AX20 V2 due to improper validation of use
Tina is a headless content management system. In versions prior to @tinacms/app 2.5.6 and tinacms 3.9.3, cross-origin po
An Open Redirect vulnerability (CWE-601) exists in the OAuth/OIDC authentication implementation of the Axivion Dashboard
Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) atta
Astro is a web framework for content-driven websites. In versions 8.1.0 through 11.0.1, when trailingSlash: 'always' is
MISP installation scripts generated an Apache HTTP virtual-host configuration containing an incorrectly formatted HTTP-t
GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsaf
The Webbox of TeamDavid by Tobit Laboratories AG constructs redirect URLs using user-supplied input, which is appended
Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to HTTP header injection through the “cType” URL par
Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the “replyUrl” parameter. An atta
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in phoenixframework phoenix_live_view allows an attack
The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, an
chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses t
Concourse is a container-based automation system written in Go. Prior to version 8.2.3, an attacker is able to craft and
Joomla Extension - yootheme.com - Open redirect in CommentController::twitterAuthenticate() in Zoo < 4.1.64 - The refere
Grav is a file-based Web platform. Prior to 3.8.5, the Login plugin twofa_cancel task accepts a client-controlled _redir
Frequently Asked Questions
What is CWE-601?
CWE-601 (CWE-601) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-601?
There are 1,953 CVE records associated with CWE-601 in our database. Of these, 31 are critical severity, 165 are high severity, and 1323 are medium severity.
How can I protect against CWE-601 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-601 using AI-powered security agents.
Detect CWE-601 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-601 vulnerabilities across your infrastructure.
Get Started