Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-58491: Warpgate runs malicious code after crafted SSO link

CVE-2026-58491 · published 19 days ago
Summary

Versions of Warpgate before 0.25.5 allow a specially crafted link to insert unwanted web page code after a user completes single sign‑on authentication. This can let an attacker view the user’s session information and, if the user is an administrator, perform actions on their behalf. Upgrade Warpgate to version 0.25.5 or later to stop the issue.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
warp-tech warpgate < 0.25.5
Original advisory text
Warpgate: Reflected XSS in SSO return endpoint via attacker-controlled next parameter
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.5, the /@warpgate/api/sso/providers/:name/start endpoint stores an attacker-controlled next parameter that the POST /@warpgate/api/sso/return handler inserts without HTML escaping into the response generated by warpgate-protocol-http/src/api/sso_provider_list.rs. A victim who follows a crafted link and completes SSO can cause markup and JavaScript to execute in the authenticated Warpgate origin, allowing access to session data and actions through user APIs, and through administrator APIs only when the victim is an administrator. The GET /@warpgate/api/sso/return path also uses the same unvalidated value as a redirect destination, enabling an open redirect. This issue is fixed in version 0.25.5.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published21 Sep 2026
Updated9 Oct 2026
First seen21 Sep 2026
Sources
CVE-2026-58491 · MITRE
Track software like this
Free during beta