{"id":"CVE-2026-49820","summary":"Probo has an open redirect bypass via path normalization","details":"Probo is a self-hostable governance, risk, and compliance (GRC) platform built for engineering and security teams. Probo's `saferedirect` package validates redirect URLs used across authentication flows (OIDC, SAML, session transfer, OAuth connectors, and trust-center magic links). Prior to version 0.19.3.1, the validator only inspected the second character of relative paths, so a URL like `/../\\evil.com` passed validation because the second character is `.`. Go's `http.Redirect` normalizes this path to `/\\evil.com` before setting the `Location` header. Browsers can interpret the backslash as a host separator and redirect the user to an external domain (`https://evil.com`), bypassing the intended same-origin restriction. This enables open-redirect phishing: an attacker can craft a `continue` parameter (or embed a malicious URL in a session-transfer token) that appears to originate from a trusted Probo domain but redirects victims elsewhere. This is fixed in `go.probo.inc/probo` 0.193.1 by normalizing relative paths with `path.Clean` before validation, rejecting backslashes (including percent-encoded `%5c`) anywhere in the path, and re-checking the normalized result for protocol-relative and backslash prefixes. Self-hosted deployments should upgrade to probod v0.194.1 or later. SaaS deployments on getprobo.com are patched. No practical workaround is available for self-hosted installations.","aliases":["GHSA-x7qq-m748-8p2c","GO-2026-5861"],"modified":"2026-08-16T03:31:28.256858939Z","published":"2026-08-13T14:36:34.645Z","related":["openSUSE-SU-2026:21483-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49820.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-601"]},"references":[{"type":"WEB","url":"https://github.com/getprobo/probo/blob/main/SECURITY_NOTES.md"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49820.json"},{"type":"ADVISORY","url":"https://github.com/getprobo/probo/security/advisories/GHSA-x7qq-m748-8p2c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49820"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/getprobo/probo","events":[{"introduced":"0"},{"fixed":"4cdf7699e836fc7217a45176eb676dc93327f1f2"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0"},{"fixed":"0.193.1"}]}}],"versions":["@probo/cookie-banner/v0.6.0","@probo/n8n-nodes-probo/v0.188.0","probod/v0.193.0","prb/v0.189.0","helm/v0.1.0","@probo/n8n-nodes-probo/v0.187.1","probod/v0.192.0","@probo/n8n-nodes-probo/v0.187.0","probod/v0.191.0","prb/v0.188.0","probod/v0.190.1","@probo/cookie-banner/v0.5.0","proboctl/v0.1.0","probod/v0.190.0","@probo/n8n-nodes-probo/v0.186.0","probod/v0.189.0","prb/v0.187.0","@probo/cookie-banner/v0.4.1","@probo/n8n-nodes-probo/v0.185.0","probod/v0.188.0","prb/v0.186.0","probod/v0.187.0","probod/v0.186.1","probod/v0.186.0","prb/v0.185.0","@probo/cookie-banner/v0.4.0","@probo/n8n-nodes-probo/v0.184.0","probod/v0.185.0","prb/v0.184.0","probod-bootstrap/v0.1.1","probod/v0.184.2","prb/v0.183.1","probod/v0.184.1","@probo/cookie-banner/v0.3.1","probod/v0.184.0","prb/v0.183.0","@probo/n8n-nodes-probo/v0.183.0","@probo/cookie-banner/v0.3.0","probod/v0.183.0","@probo/n8n-nodes-probo/v0.182.0","probod/v0.182.0","prb/v0.182.0","v0.181.0","v0.180.0","v0.179.1","v0.179.0","v0.178.0","v0.177.1","v0.177.0","v0.176.1","v0.176.0","v0.175.0","v0.174.0","v0.173.0","v0.172.1","v0.172.0","v0.171.1","v0.171.0","v0.170.0","v0.169.1","v0.169.0","v0.168.2","v0.168.1","v0.168.0","v0.167.0","v0.166.0","v0.165.3","v0.165.2","v0.165.1","v0.165.0","v0.164.0","v0.163.2","v0.163.1","v0.163.0","v0.162.1","v0.162.0","v0.161.2","v0.161.1","v0.161.0","v0.160.2","v0.160.1","v0.160.0","v0.159.0","v0.158.0","v0.157.0","v0.156.1","v0.156.0","v0.155.0","v0.154.2","v0.154.1","v0.154.0","v0.153.2","v0.153.1","v0.153.0","v0.152.0","v0.151.0","v0.150.0","v0.149.1","v0.149.0","v0.148.0","v0.147.0","v0.146.1","v0.146.0","v0.145.0","v0.144.0","v0.143.0","v0.142.2","v0.142.1","v0.142.0","v0.141.0","v0.140.0","v0.139.0","v0.138.2","v0.138.1","v0.138.0","v0.137.3","v0.137.2","v0.137.1","v0.137.0","v0.136.0","v0.135.1","v0.135.0","v0.134.3","v0.134.2","v0.134.1","v0.134.0","v0.133.0","v0.132.0","v0.131.2","v0.131.1","v0.131.0","v0.130.3","v0.130.2","v0.130.1","v0.130.0","v0.129.3","v0.129.2","v0.129.1","v0.129.0","v0.128.0","v0.127.1","v0.127.0","v0.126.1","v0.126.0","v0.125.1-4","v0.125.1-3","v0.125.1-2","v0.125.1-1","v0.125.1","v0.125.0","v0.124.2","v0.124.1","v0.124.0","v0.123.3","v0.123.2","v0.123.1","v0.123.0","v0.122.0","v0.121.1","v0.121.0","v0.120.0","v0.119.1","v0.119.0","v0.118.2","v0.118.1","v0.118.0","v0.117.3","v0.117.2","v0.117.1","v0.117.0","v0.116.15","v0.116.14","v0.116.13","v0.116.12","v0.116.11","v0.116.10","v0.116.9","v0.116.8","v0.116.7","v0.116.6","v0.116.5","v0.116.4","v0.116.3","v0.116.2","v0.116.1","v0.116.0","v0.115.0","v0.114.0","v0.113.0","v0.112.4","v0.112.3","v0.112.2","v0.112.1","v0.112.0","v0.111.2","v0.111.1","v0.111.0","v0.110.2","v0.110.1","v0.110.0","v0.109.0","v0.108.0","v0.107.1","v0.107.0","v0.106.0","v0.105.0","v0.104.0","v0.103.0","v0.102.0","v0.101.1","v0.101.0","v0.100.0","v0.99.0","v0.98.1","v0.98.0","v0.97.0","v0.96.1","v0.96.0","v0.95.0","v0.94.2","v0.94.1","v0.94.0","v0.93.0","v0.92.0","v0.91.0","v0.90.1","v0.90.0","v0.89.1","v0.89.0","v0.88.8","v0.88.7","v0.88.6","v0.88.5","v0.88.3","v0.88.2","v0.88.1","v0.88.0","v0.87.0","v0.86.4","v0.86.3","v0.86.2","v0.86.1","v0.86.0","v0.85.0","v0.84.0","v0.83.0","v0.82.0","v0.81.0","v0.80.2","v0.80.1","v0.80.0","v0.79.0","v0.78.0","v0.77.0","v0.76.0","v0.75.1","v0.75.0","v0.74.7","v0.74.6","v0.74.5","v0.74.4","v0.74.3","v0.74.2","v0.74.1","v0.74.0","v0.73.1","v0.73.0","v0.72.0","v0.71.0","v0.70.0","v0.69.0","v0.68.3","v0.68.2","v0.68.1","v0.68.0","v0.67.2","v0.67.1","v0.67.0","v0.66.1","v0.66.0","v0.65.1","v0.65.0","v0.64.1","v0.64.0","v0.63.1","v0.63.0","v0.62.0","v0.61.1","v0.61.0","v0.60.0","v0.59.1","v0.59.0","v0.58.4","v0.58.3","v0.58.2","v0.58.1","v0.58.0","v0.57.1","v0.57.0","v0.56.0","v0.55.0","v0.54.0","v0.53.0","v0.52.0","v0.51.1","v0.51.0","v0.50.1","v0.50.0","v0.49.0","v0.48.1","v0.48.0","v0.47.0","v0.46.2","v0.46.1","v0.46.0","v0.45.1","v0.45.0","v0.44.0","v0.43.1","v0.43.0","v0.42.1","v0.42.0","v0.41.0","v0.40.0","v0.39.0","v0.38.1","v0.38.0","v0.37.5","v0.37.4","v0.37.3","v0.37.2","v0.37.1","v0.37.0","v0.36.0","v0.35.0","v0.34.0","v0.33.6","v0.33.5","v0.33.4","v0.33.3","v0.33.2","v0.33.1","v0.33.0","v0.32.0","v0.31.0","v0.30.1","v0.30.0","v0.29.0","v0.28.0","v0.27.1","v0.27.0","v0.26.0","v0.25.0","v0.24.0","v0.23.1","v0.23.0","v0.22.0","v0.21.0","v0.20.1","v0.20.0","v0.19.2","v0.19.1","v0.19.0","v0.18.1","v0.18.0","v0.17.0","v0.16.0","v0.15.1","v0.15.0","v0.14.0","v0.13.2","v0.13.1","v0.13.0","v0.12.0","v0.11.1","v0.11.0","v0.10.1","v0.10.0","v0.9.0","v0.8.0","v0.7.0","v0.6.0","v0.5.0","v0.4.2","v0.4.1","v0.4.0","v0.2.0","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49820.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N"}]}