top of page
< Back

Open Redirect

Open redirect occurs when an application redirects users based on unvalidated or weakly validated URL parameters. Attackers may abuse this behavior to make phishing links appear trusted, bypass security filters, steal credentials, or support social engineering campaigns. While open redirect severity depends on context, it becomes more impactful when used in login flows, OAuth redirects, password reset links, payment journeys, or enterprise authentication systems.

Redirect URL Provided → URL Not Validated → User Sent to Malicious Site → Phishing Risk Created → Trusted Redirect Allowlist Applied

bottom of page