CVE-2026-91165: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in warp-tech warpgate
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.27.6, the response_mode=form_post SSO return path in warpgate-protocol-http/src/api/sso_provider_list.rs uses serde_json::to_string inside ReturnToSsoPostResponse without neutralizing a script-closing sequence. The vulnerable value can enter the script block through the attacker-controlled next redirect parameter stored by warpgate-protocol-http/src/api/sso_provider_detail.rs or through IdP-derived error messages that make_redirect_url concatenates without URL encoding. The IdP-derived path is reachable when the attacker controls a configured identity provider, or when the attacker controls the email or username claim on an attacker-controlled account and the configured identity provider permits the required unvalidated claim format. A victim must complete the form_post SSO flow for the injected markup to be rendered. The Warpgate Content-Security-Policy blocks injected JavaScript and event handlers, so the demonstrated impact is content spoofing, a false login form, or a meta refresh rather than script execution. This issue is fixed in version 0.27.6.
AI Analysis
Technical Summary
Warpgate versions before 0.27.6 have an XSS vulnerability in the SSO return path when response_mode=form_post is used. The vulnerability arises because the code uses serde_json::to_string without properly neutralizing script-closing sequences in attacker-controlled input parameters, such as the next redirect parameter or IdP-derived error messages. An attacker controlling an identity provider or certain claims can inject markup that is rendered when a victim completes the form_post SSO flow. The Content-Security-Policy blocks JavaScript execution, limiting impact to content spoofing rather than script execution. The issue is resolved in version 0.27.6.
Potential Impact
The vulnerability does not allow script execution due to Content-Security-Policy restrictions but can be exploited to spoof content, such as displaying false login forms or triggering meta refresh redirects. This could potentially mislead users but does not compromise confidentiality or availability. The CVSS score is 2.4 (low severity), reflecting limited impact.
Mitigation Recommendations
Upgrade warpgate to version 0.27.6 or later, where this vulnerability is fixed. No other mitigations are specifically required as the Content-Security-Policy already blocks script execution and event handlers.
CVE-2026-91165: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in warp-tech warpgate
Description
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.27.6, the response_mode=form_post SSO return path in warpgate-protocol-http/src/api/sso_provider_list.rs uses serde_json::to_string inside ReturnToSsoPostResponse without neutralizing a script-closing sequence. The vulnerable value can enter the script block through the attacker-controlled next redirect parameter stored by warpgate-protocol-http/src/api/sso_provider_detail.rs or through IdP-derived error messages that make_redirect_url concatenates without URL encoding. The IdP-derived path is reachable when the attacker controls a configured identity provider, or when the attacker controls the email or username claim on an attacker-controlled account and the configured identity provider permits the required unvalidated claim format. A victim must complete the form_post SSO flow for the injected markup to be rendered. The Warpgate Content-Security-Policy blocks injected JavaScript and event handlers, so the demonstrated impact is content spoofing, a false login form, or a meta refresh rather than script execution. This issue is fixed in version 0.27.6.
CVSS v3.1
Score 2.4low
Affected software
warp-tech
warpgate
pkg:github/warp-tech/warpgateRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Warpgate versions before 0.27.6 have an XSS vulnerability in the SSO return path when response_mode=form_post is used. The vulnerability arises because the code uses serde_json::to_string without properly neutralizing script-closing sequences in attacker-controlled input parameters, such as the next redirect parameter or IdP-derived error messages. An attacker controlling an identity provider or certain claims can inject markup that is rendered when a victim completes the form_post SSO flow. The Content-Security-Policy blocks JavaScript execution, limiting impact to content spoofing rather than script execution. The issue is resolved in version 0.27.6.
Potential Impact
The vulnerability does not allow script execution due to Content-Security-Policy restrictions but can be exploited to spoof content, such as displaying false login forms or triggering meta refresh redirects. This could potentially mislead users but does not compromise confidentiality or availability. The CVSS score is 2.4 (low severity), reflecting limited impact.
Mitigation Recommendations
Upgrade warpgate to version 0.27.6 or later, where this vulnerability is fixed. No other mitigations are specifically required as the Content-Security-Policy already blocks script execution and event handlers.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-09-14T21:20:41.196Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab17f3e55bf5e2cf554e7c0
Added to database: 09/21/2026, 19:02:22 UTC
Last enriched: 09/21/2026, 19:17:19 UTC
Last updated: 09/21/2026, 19:52:45 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.