{"id":"GHSA-grh9-37g7-53mj","aliases":["GO-2026-4398"],"url":"https://o3.security/vulnerability/GHSA-grh9-37g7-53mj","summary":"WireGuard Portal v2 has Open Redirect Vulnerability in OAuth Authentication Flow","details":"### Summary\nAn Open Redirect vulnerability exists in the OAuth authentication flow that allows attackers to redirect users to external malicious websites after authentication. The vulnerability is caused by insufficient validation of the return parameter in the OAuth login initialization endpoint.\n\n### Patches\nThe problem was fixed in the latest release, v2.1.2. The [docker images](https://hub.docker.com/r/wgportal/wg-portal) for the tag 'latest' built from the master branch also include the fix.","published":"2026-02-02T21:16:49Z","modified":"2026-02-05T09:56:23.468869Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/h44z/wg-portal","fixedVersion":"2.1.2"}],"fix":{"url":"https://github.com/h44z/wg-portal/commit/e62db0d62ebabbec39c767b953b92fb4b4d08a81","label":"h44z/wg-portal@e62db0d"},"references":[{"type":"WEB","url":"https://github.com/h44z/wg-portal/security/advisories/GHSA-grh9-37g7-53mj"},{"type":"WEB","url":"https://github.com/h44z/wg-portal/commit/e62db0d62ebabbec39c767b953b92fb4b4d08a81"},{"type":"PACKAGE","url":"https://github.com/h44z/wg-portal"},{"type":"WEB","url":"https://github.com/h44z/wg-portal/releases/tag/v2.1.2"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-02-05T09:56:23.468869Z"}}