GHSA-437j-5qc3-c589 is a medium-severity (CVSS 6.1) Open Redirect vulnerability in microweber/microweber. 1 public exploit reference exists, so weaponization risk is real. A fix is available for microweber/microweber — see the affected versions and patch details below.
Open Redirect in microweber
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
GHSA-437j-5qc3-c589 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.
Where this sits among everything scored
Of 379,842 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.
Real-World Exposure
microweber/microweberReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects Packagist packages — download data is not available via public APIs for these ecosystems.
Description
Open Redirect in GitHub repository microweber/microweber prior to 1.2.19.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 🐘Packagist | microweber/microweber | all versions | 1.2.19composer require microweber/microweber:^1.2.19 |
Affected Products
microwebermicroweberResearch use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for microweber/microweber, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update microweber/microweber to 1.2.19 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-437j-5qc3-c589 is resolved across your whole dependency graph.
Workarounds
Stop reflecting attacker-controlled destinations: resolve every redirect target against an allowlist of paths or hosts you own, prefer a server-side key over a full URL in the request, and reject absolute URLs entirely where the flow only ever needs a relative one.
Frequently Asked Questions
Is GHSA-437j-5qc3-c589 in your dependencies?
Find it across Packagist, including transitive dependencies.