CVE-2026-53989
4.7 MEDIUMpublic exploit availablePublished 2026-09-29 · Updated 2026-09-29
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Dockhand before 1.0.36 contains an open redirect vulnerability in the OIDC initiation endpoint that allows unauthenticated remote attackers to redirect authenticated users to attacker-controlled sites by injecting an unvalidated redirect query parameter. Attackers can craft a malicious link targeting the OIDC callback flow to capture authorization codes via the Referer header and conduct follow-up credential phishing against any Dockhand account after a legitimate login.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
Weaknesses
CWE-601
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-100523PoC
- CRITICALCVE-2026-101090PoC
- UNSCOREDCVE-2026-101907PoC
- UNSCOREDCVE-2026-103048
- MEDIUMCVE-2026-14219
- MEDIUMCVE-2026-16296
- MEDIUMCVE-2026-18505
- MEDIUMCVE-2026-54915PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.