CVE-2026-55252

medium

Description

OpenRun is an open-source, self-hosted GitOps platform for deploying web apps and internal tools to Docker or Kubernetes. Prior to version 0.17.7, the restrictions on redirect URLs in openrun can be bypassed by attackers, leading to open redirect attacks. This issue has been patched in version 0.17.7.

References

https://github.com/openrundev/openrun/security/advisories/GHSA-h5g6-xmh4-hc37

https://github.com/openrundev/openrun/releases/tag/v0.17.7

https://github.com/openrundev/openrun/commit/709da784fcf1311c85f30f3542cfa3601a78bbf0

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-91046

Details

Source: Mitre, NVD

Published: 2026-10-01

Updated: 2026-10-02

Risk Information

CVSS v2

Base Score: 5.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 6.1

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Severity: Medium

CVSS v4

Base Score: 5.1

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N

Severity: Medium

EPSS

EPSS: 0.00321