Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-58491: Warpgate runs malicious code after crafted SSO link
CVE-2026-58491 · published 19 days ago
Summary
Versions of Warpgate before 0.25.5 allow a specially crafted link to insert unwanted web page code after a user completes single sign‑on authentication. This can let an attacker view the user’s session information and, if the user is an administrator, perform actions on their behalf. Upgrade Warpgate to version 0.25.5 or later to stop the issue.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| warp-tech | warpgate | < 0.25.5 |
Original advisory text
Warpgate: Reflected XSS in SSO return endpoint via attacker-controlled next parameter
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.5, the /@warpgate/api/sso/providers/:name/start endpoint stores an attacker-controlled next parameter that the POST /@warpgate/api/sso/return handler inserts without HTML escaping into the response generated by warpgate-protocol-http/src/api/sso_provider_list.rs. A victim who follows a crafted link and completes SSO can cause markup and JavaScript to execute in the authenticated Warpgate origin, allowing access to session data and actions through user APIs, and through administrator APIs only when the victim is an administrator. The GET /@warpgate/api/sso/return path also uses the same unvalidated value as a redirect destination, enabling an open redirect. This issue is fixed in version 0.25.5.
References
- https://github.com/warp-tech/warpgate/security/advisories/GHSA-3c3w-75j2-7h74
- https://github.com/warp-tech/warpgate/commit/eab0548f018d95b5f96f8e913527000e05e...
- https://github.com/warp-tech/warpgate/releases/tag/v0.25.5
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58491... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-58491 Vendor Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published21 Sep 2026
Updated9 Oct 2026
First seen21 Sep 2026
Track software like this
Free during beta