{"id":"CVE-2025-69725","aliases":["GHSA-mqqf-5wvp-8fh8","GO-2026-4316"],"url":"https://o3.security/vulnerability/CVE-2025-69725","summary":"chi has an open redirect vulnerability in the RedirectSlashes middleware","details":"An Open Redirect vulnerability in the go-chi/chi >=5.2.2 RedirectSlashes function allows remote attackers to redirect victim users to malicious websites using the legitimate website domain.","published":"2026-02-19T17:24:39.830Z","modified":"2026-07-10T10:14:35.579761132Z","cvss":{"score":4.7,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/go-chi/chi/v5","fixedVersion":"5.2.4"}],"fix":null,"references":[{"type":"WEB","url":"http://go-chichi.com"},{"type":"ADVISORY","url":"https://github.com/go-chi/chi/security/advisories/GHSA-mqqf-5wvp-8fh8"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-10T10:14:35.579761132Z"}}