Open Redirect Affecting local-deep-research package, versions [,1.0.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Open Redirect vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-LOCALDEEPRESEARCH-13506860
  • published10 Oct 2025
  • disclosed2 Oct 2025
  • creditUnknown

Introduced: 2 Oct 2025

CVE NOT AVAILABLE CWE-601  (opens in a new tab)

How to fix?

Upgrade local-deep-research to version 1.0.0 or higher.

Overview

local-deep-research is an AI-powered research assistant with deep, iterative analysis using LLMs and web searches

Affected versions of this package are vulnerable to Open Redirect via the next_page query parameter in the post-authentication redirection flow. An attacker can exploit this vulnerability by supplying a crafted next_page value to the local_deep_research.web.auth.routes.login handler, causing users to be redirected to an attacker-controlled domain after login, which can facilitate phishing attacks or credential theft.

References

CVSS Base Scores

version 4.0
version 3.1