{"id":"CVE-2025-65581","aliases":["GHSA-vfm5-cr22-jg3m"],"url":"https://o3.security/vulnerability/CVE-2025-65581","summary":"ABP Account Module has an Open Redirect through Improper validation in its register function","details":"An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improper validation of the returnUrl parameter in the register function allows an attacker to redirect users to arbitrary external domains.","published":"2025-12-16T00:00:00Z","modified":"2026-07-15T01:49:02.784646055Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"NuGet","name":"Volo.Abp.Account.Web","fixedVersion":"10.0.0-rc.2"}],"fix":{"url":"https://github.com/abpframework/abp/commit/44a2dc14e933f3ce1ca93f9313d836694ab77d1d","label":"abpframework/abp@44a2dc1"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/65xxx/CVE-2025-65581.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-65581"},{"type":"FIX","url":"https://github.com/abpframework/abp/commit/44a2dc14e933f3ce1ca93f9313d836694ab77d1d"},{"type":"FIX","url":"https://github.com/abpframework/abp/commit/a01adc58464d278ca817c4bbb6cbce30f155d0d1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:02.784646055Z"}}