GPU VulnDB

Database/Container, Kubernetes & orchestration

OpenRun: redirect URL restrictions can be bypassed, giving an open redirect on the deploy console

CVSS 5.1CVE-2026-55252Container, Kubernetes & orchestrationcurated

Impact

OpenRun is a self-hosted GitOps platform that deploys apps to Docker or Kubernetes, so its web console is an operator-facing control surface with credentials for the clusters it pushes to. Before 0.17.7 its redirect URL restrictions can be bypassed, so an attacker-supplied link routed through the console sends an operator to an arbitrary external site. On its own this yields no access to the cluster: it is a phishing and credential-harvesting primitive against the people who hold deploy rights, and the record describes no code execution or token theft. Treat it as hygiene on an in-scope control-plane component rather than an urgent cluster exposure.

Who can reach it

Remote and unauthenticated to trigger, but it needs a victim to follow the crafted link - the useful target is an operator with an OpenRun session, so the real precondition is getting a link in front of someone who can deploy.

What to do

Upgrade OpenRun to 0.17.7, which carries the fix. That is a restart of the OpenRun service; running workloads already deployed to Docker or Kubernetes are not touched, and no node drain or reboot is involved.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.