Open Redirect Affecting @saltcorn/server package, versions <1.4.6>=1.5.0-beta.0 <1.5.6>=1.6.0-alpha.0 <1.6.0-beta.5


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.02% (5th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Open Redirect vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-SALTCORNSERVER-16111017
  • published20 Apr 2026
  • disclosed16 Apr 2026
  • creditUnknown

Introduced: 16 Apr 2026

CVE-2026-42259  (opens in a new tab)
CWE-601  (opens in a new tab)

How to fix?

Upgrade @saltcorn/server to version 1.4.6, 1.5.6, 1.6.0-beta.5 or higher.

Overview

@saltcorn/server is a Server app for Saltcorn, open-source no-code platform

Affected versions of this package are vulnerable to Open Redirect via the is_relative_url function. An attacker can redirect users to an external, attacker-controlled domain by crafting a malicious URL that exploits improper validation of the dest parameter in the login.

Note: This can be achieved by tricking a user into clicking a specially crafted login link, leading to potential credential phishing or other social engineering attacks.

CVSS Base Scores

version 4.0
version 3.1