mediumCVSS 6.1Vulnerability

GHSA-grh9-37g7-53mj

### Summary An Open Redirect vulnerability exists in the OAuth authentication flow that allows attackers to redirect users to external malicious websites after authentication. The vulnerability is caused by insufficient validation of the return parameter in the OAuth login initialization endpoint. ### Patches The problem was fixed in the latest release, v2.1.2. The [docker images](https://hub.docker.com/r/wgportal/wg-portal) for the tag 'latest' built from the master branch also include the fix.

Properties

ghsa_id
GHSA-grh9-37g7-53mj
severity
medium
summary
WireGuard Portal v2 has Open Redirect Vulnerability in OAuth Authentication Flow
cvss_score
6.1
cve_id
GHSA-grh9-37g7-53mj
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
is_ghsa_only
true
ghsa_published
2026-02-02T21:16:49Z
source_url
https://github.com/advisories/GHSA-grh9-37g7-53mj
ghsa_updated
2026-02-02T21:16:49Z

Related Entities (3)

REPORTED_BY (1)

[Source]GitHub Advisory Database

AFFECTS (1)

[Software]go/github.com/h44z/wg-portal

HAS_WEAKNESS (1)

[Weakness]URL Redirection to Untrusted Site ('Open Redirect')

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-grh9-37g7-53mj (CVSS 6.1) — Ninja Signal Threat Intelligence | Ninja Signal