CVE-2026-49996: CWE-601: URL Redirection to Untrusted Site ('Open Redirect') in freedomofpress securedrop-client
SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. Prior to version 1.3.1, a malicious SecureDrop Server could bypass securedrop-proxy's origin limitation by responding with cross-origin redirects. SecureDrop Server itself has multiple layers of built-in hardening, and is a dedicated physical machine exposed on the internet only via Tor hidden services for the Source and Journalist interfaces, and optionally via remote SSH access over another Tor hidden service. A newsroom's SecureDrop Workstation communicates only with its own dedicated SecureDrop Server. Version 1.3.1 fixes the issue.
AI Analysis
Technical Summary
The securedrop-client desktop app used by journalists to securely communicate with sources had an open redirect vulnerability (CWE-601) before version 1.3.1. A malicious SecureDrop Server could exploit this by responding with cross-origin redirects, circumventing the origin limitation enforced by securedrop-proxy. The SecureDrop Server environment is hardened and accessed exclusively via Tor hidden services, reducing the attack surface. The issue was addressed and fixed in version 1.3.1 of securedrop-client.
Potential Impact
The vulnerability allows a malicious SecureDrop Server to perform cross-origin redirects, potentially redirecting the client to untrusted sites. However, due to the SecureDrop Server's hardened deployment and restricted access via Tor hidden services, the practical impact is limited. The CVSS score of 3.7 reflects a low confidentiality impact with no integrity or availability impact.
Mitigation Recommendations
Upgrade securedrop-client to version 1.3.1 or later, where this open redirect vulnerability has been fixed. No other specific mitigations are indicated. Since the vulnerability is fixed in 1.3.1, applying this official update fully addresses the issue.
CVE-2026-49996: CWE-601: URL Redirection to Untrusted Site ('Open Redirect') in freedomofpress securedrop-client
Description
SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. Prior to version 1.3.1, a malicious SecureDrop Server could bypass securedrop-proxy's origin limitation by responding with cross-origin redirects. SecureDrop Server itself has multiple layers of built-in hardening, and is a dedicated physical machine exposed on the internet only via Tor hidden services for the Source and Journalist interfaces, and optionally via remote SSH access over another Tor hidden service. A newsroom's SecureDrop Workstation communicates only with its own dedicated SecureDrop Server. Version 1.3.1 fixes the issue.
CVSS v3.1
Score 3.7low
Affected software
pkg:github/freedomofpress/securedrop-clientRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The securedrop-client desktop app used by journalists to securely communicate with sources had an open redirect vulnerability (CWE-601) before version 1.3.1. A malicious SecureDrop Server could exploit this by responding with cross-origin redirects, circumventing the origin limitation enforced by securedrop-proxy. The SecureDrop Server environment is hardened and accessed exclusively via Tor hidden services, reducing the attack surface. The issue was addressed and fixed in version 1.3.1 of securedrop-client.
Potential Impact
The vulnerability allows a malicious SecureDrop Server to perform cross-origin redirects, potentially redirecting the client to untrusted sites. However, due to the SecureDrop Server's hardened deployment and restricted access via Tor hidden services, the practical impact is limited. The CVSS score of 3.7 reflects a low confidentiality impact with no integrity or availability impact.
Mitigation Recommendations
Upgrade securedrop-client to version 1.3.1 or later, where this open redirect vulnerability has been fixed. No other specific mitigations are indicated. Since the vulnerability is fixed in 1.3.1, applying this official update fully addresses the issue.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-02T18:30:51.283Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a8750b5acd9273b490631f9
Added to database: 08/20/2026, 19:08:37 UTC
Last enriched: 08/20/2026, 19:22:22 UTC
Last updated: 08/20/2026, 19:55:46 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.